Junglewise Threat Intelligence

CVE-2026-58074: Veeam ONE privileged code execution

CVE-2026-58074 · Severity: info · CVSS 8.6 · Published 2026-08-04

Vendors: Veeam.

Executive brief

Veeam ONE is monitoring and reporting software used to manage virtualization environments. A high-privileged user can exploit this vulnerability to execute arbitrary code on the Veeam ONE server, potentially compromising backup and recovery operations and gaining control of critical infrastructure management systems.

Technical details

CVE-2026-58074 is a code execution vulnerability in Veeam ONE that requires high-privileged user access to exploit. The vulnerability allows an authenticated attacker with elevated privileges to execute arbitrary code on the Veeam ONE server through a network vector. The root cause and vulnerable component are not explicitly detailed in the advisory, but the high CVSS score and multiple impact categories (confidentiality, integrity, availability all high) indicate full system compromise is possible. Patches are available in Veeam ONE 13.1 (build 13.1.0.7034), 13.0.2 Patch 1 (build 13.0.2.7159), and 12.3 Patch 1 (build 12.3.0.7165); all earlier versions remain vulnerable.

Affected products

  • Veeam ONE 13.0.2.6723 and earlier 13.x builds; 12.3.0.4670 and earlier 12.x builds

Timeline

  • 2026-08-04: disclosed
  • 2026-08-04: patched: Patches released same day as disclosure: Veeam ONE 13.1, 13.0.2 Patch 1, 12.3 Patch 1

References