Junglewise Threat Intelligence

CVE-2026-58075: Veeam ONE arbitrary file read in web service

CVE-2026-58075 · Severity: info · CVSS 8.7 · Published 2026-08-04

Vendors: Veeam.

Executive brief

Veeam ONE is a software platform that monitors and manages virtualized infrastructure. An unauthenticated attacker can remotely read arbitrary files from the host system through the web service, potentially exposing sensitive configuration, credentials, or system data that could be used to escalate privileges and gain deeper control of the environment.

Technical details

CVE-2026-58075 is an arbitrary file read vulnerability in Veeam ONE's web service accessible over the network without authentication. The vulnerability allows an unauthenticated remote attacker to read arbitrary files from the host system. The root cause appears to be improper input validation or path traversal handling in a file-serving component. An attacker can leverage the disclosed files to identify system configuration, credentials, or other sensitive data to escalate privileges locally. The vulnerability affects Veeam ONE 13.0.2.6723 and earlier version 13 builds; versions 12.x are not affected. Patches are available in Veeam ONE 13.1.0.7034 and later, as well as 13.0.2 Patch 1 (build 13.0.2.7159).

Affected products

  • Veeam ONE 13.0.2.6723 and all earlier version 13 builds

Timeline

  • 2026-08-04: disclosed
  • 2026-08-04: patched: Patches released in Veeam ONE 13.1.0.7034 and 13.0.2.7159

References