Executive brief
Veeam Backup & Replication, used for data protection and disaster recovery, stores guest operating system credentials in cleartext within log files on guest machines during Application-Aware processing. A local user with read access to these logs can retrieve privileged account credentials, potentially allowing unauthorized administrative access to guest systems.
Technical details
The vulnerability is an insecure logging issue in Veeam Backup & Replication's Application-Aware processing feature. Guest OS credentials used for this processing are written in cleartext to log files stored on the guest machine. An attacker with local access and read permissions to log files can recover these credentials, gaining privileged access to guest systems. The attack requires local file system access (not network-based) and applies to Windows-based deployments running version 13.0.2.29 and earlier 13.x builds. Fixes are available in Veeam Backup & Replication 13.1.0.411 and 13.0.3.63. Organizations should patch immediately and reset affected credentials, as existing log files are not automatically remediated.
Affected products
- Veeam Backup & Replication 13.0.2.29 and earlier 13.x builds
Timeline
- 2026-08-26: disclosed: Vulnerability published on NVD
- 2026-08-25: patched: Fix released in Veeam Backup & Replication 13.1.0.411 and 13.0.3.63