Executive brief
Veeam Backup & Replication is a data protection solution used to back up and restore virtual and physical workloads. A security vulnerability in high availability deployments allows an authorized Backup Administrator to execute arbitrary commands on the system. This could lead to a complete takeover of the backup infrastructure and potential access to sensitive backed-up data.
Technical details
A remote code execution (RCE) vulnerability exists in Veeam Backup & Replication high availability (HA) deployments due to improper control of generation of code (CWE-94). The flaw is specifically present in the Veeam Software Appliance deployment type. An attacker must be authenticated with the high-privileged 'Backup Administrator' role to exploit this vulnerability. Successful exploitation allows for full system compromise with a CVSS 3.1 score of 9.1. The issue is resolved in Veeam Backup & Replication version 13.0.1.2067.
Affected products
- Veeam Veeam Backup & Replication 13.0.0.496 through 13.0.1.1071
Timeline
- 2026-03-12: disclosed
- 2026-03-12: advisory
- 2026-03-12: patched: Fixed in version 13.0.1.2067