Executive brief
Veeam ONE is a monitoring and reporting tool used by organizations to track backup infrastructure and system health. A vulnerability allows a low-privileged user to access report data beyond their authorized scope by circumventing shared report link restrictions. While the reported severity is low, this represents a data exposure risk where users could view sensitive monitoring or operational information they should not have access to.
Technical details
The vulnerability is an authorization bypass affecting Veeam ONE's shared report link mechanism. A low-privileged user can bypass access controls to retrieve report data outside the intended scope of a shared report link, indicating insufficient scope validation or token/session binding. The attack requires network access to the Veeam ONE server and an authenticated session with low privileges. This allows unauthorized information disclosure of reports that should be restricted to specific users or groups. Patch availability is indicated through Veeam ONE 13.1 and earlier version patches as referenced in KB4892.
Affected products
- Veeam ONE 13.0.2.6723 and earlier version 13 builds; 12.x and earlier
Timeline
- 2026-08-04: disclosed