Executive brief
Veeam Backup & Replication is a data protection solution used to back up, restore, and replicate critical business data. A security vulnerability allows a user with 'Backup Viewer' permissions to execute unauthorized commands on the underlying database server. This could lead to a complete takeover of the backup infrastructure, potentially allowing an attacker to delete backups or steal sensitive corporate data.
Technical details
A SQL injection vulnerability (CWE-89) exists in Veeam Backup & Replication that allows an authenticated user with the 'Backup Viewer' role to achieve remote code execution. The flaw enables the attacker to execute arbitrary commands with the privileges of the 'postgres' service account. This vulnerability affects both Windows-based deployments and the Veeam Software Appliance. The issue is reachable over the network without user interaction, provided the attacker has valid low-privileged credentials. The vulnerability is resolved in versions 12.3.2.4465 and 13.0.1.2067.
Affected products
- Veeam Veeam Backup & Replication 12.0.0.1402 up to (excluding) 12.3.2.4465; 13.0.1.1071 and all earlier version 13 builds
Timeline
- 2026-03-12: disclosed
- 2026-03-12: advisory
- 2026-03-12: patched