Executive brief
Veeam ONE is a software platform that monitors and manages virtualized infrastructure. An unauthenticated attacker can remotely read arbitrary files from the host system through the web service, potentially exposing sensitive configuration, credentials, or system data that could be used to escalate privileges and gain deeper control of the environment.
Technical details
CVE-2026-58075 is an arbitrary file read vulnerability in Veeam ONE's web service accessible over the network without authentication. The vulnerability allows an unauthenticated remote attacker to read arbitrary files from the host system. The root cause appears to be improper input validation or path traversal handling in a file-serving component. An attacker can leverage the disclosed files to identify system configuration, credentials, or other sensitive data to escalate privileges locally. The vulnerability affects Veeam ONE 13.0.2.6723 and earlier version 13 builds; versions 12.x are not affected. Patches are available in Veeam ONE 13.1.0.7034 and later, as well as 13.0.2 Patch 1 (build 13.0.2.7159).
Affected products
- Veeam ONE 13.0.2.6723 and all earlier version 13 builds
Timeline
- 2026-08-04: disclosed
- 2026-08-04: patched: Patches released in Veeam ONE 13.1.0.7034 and 13.0.2.7159