Executive brief
A vulnerability in the update component of Veeam's Linux-based backup appliances could allow a user with existing access to take full control of the system. By exploiting this flaw, an attacker could gain root-level privileges, potentially leading to the theft of backup data, service disruption, or further compromise of the backup infrastructure. Most systems will receive a fix automatically, but isolated environments require manual intervention to ensure data remains protected.
Technical details
A path traversal vulnerability (CWE-22) exists in the Veeam Updater component used in Linux-based Veeam Software and Infrastructure Appliances. A local attacker with high privileges can exploit this flaw to bypass directory restrictions, leading to full root-level access to the underlying operating system. The vulnerability is specific to the Linux-based appliance versions and does not affect Windows-based backup servers. The issue is resolved in Veeam Updater version 12.3.0.65, which is typically deployed via automatic updates unless the appliance is air-gapped or lacks internet access.
Affected products
- Veeam Veeam Software Appliance Updater component versions prior to 12.3.0.65
- Veeam Veeam Infrastructure Appliance Updater component versions prior to 12.3.0.65
- Veeam Veeam Backup & Replication (Linux-based) Versions prior to 13.0.2
Timeline
- 2026-07-14: advisory: Veeam published KB4879
- 2026-07-21: disclosed: CVE published to NVD dataset