Executive brief
A vulnerability in Veeam Backup & Replication allows a user with low-level access to the system to extract saved SSH credentials. This software is used by organizations to manage and protect their data backups. If exploited, an attacker could gain unauthorized access to other servers and infrastructure connected to the backup environment, potentially leading to broader data breaches or system compromise.
Technical details
A credential disclosure vulnerability (CWE-522) exists in Veeam Backup & Replication and the Veeam Software Appliance. The flaw allows an authenticated user with low privileges to extract saved SSH credentials from the system. The vulnerability stems from insufficiently protected credentials within the application's management of stored secrets. An attacker with network access and valid low-privileged credentials can exploit this to gain high-impact confidentiality access (CVSS C:H) and potentially pivot to other systems. The issue is resolved in Veeam Backup & Replication version 13.0.1.2067.
Affected products
- Veeam Veeam Backup & Replication 13.0.0.496 through 13.0.1.1071
- Veeam Veeam Software Appliance 13.x versions prior to 13.0.1.2067
Timeline
- 2026-03-12: disclosed
- 2026-03-12: advisory
- 2026-03-12: patched: Fixed in build 13.0.1.2067