Junglewise Threat Intelligence

CVE-2026-56844: Veeam Software Appliance path traversal in Updater component

CVE-2026-56844 · Severity: info · CVSS 8.4 · Published 2026-07-22

Executive brief

A vulnerability in the update component of Veeam's Linux-based backup appliances could allow a user with existing access to take full control of the system. By exploiting this flaw, an attacker could gain root-level privileges, potentially leading to the theft of backup data, service disruption, or further compromise of the backup infrastructure. Most systems will receive a fix automatically, but isolated environments require manual intervention to ensure data remains protected.

Technical details

A path traversal vulnerability (CWE-22) exists in the Veeam Updater component used in Linux-based Veeam Software and Infrastructure Appliances. A local attacker with high privileges can exploit this flaw to bypass directory restrictions, leading to full root-level access to the underlying operating system. The vulnerability is specific to the Linux-based appliance versions and does not affect Windows-based backup servers. The issue is resolved in Veeam Updater version 12.3.0.65, which is typically deployed via automatic updates unless the appliance is air-gapped or lacks internet access.

Affected products

  • Veeam Veeam Software Appliance Updater component versions prior to 12.3.0.65
  • Veeam Veeam Infrastructure Appliance Updater component versions prior to 12.3.0.65
  • Veeam Veeam Backup & Replication (Linux-based) Versions prior to 13.0.2

Timeline

  • 2026-07-14: advisory: Veeam published KB4879
  • 2026-07-21: disclosed: CVE published to NVD dataset

References

Related threats