Executive brief
Veeam ONE is a comprehensive monitoring and analytics platform for virtualized infrastructure. A low-privileged user can inject SQL commands to extract sensitive database contents, potentially exposing customer data, backup metadata, and system configurations used by organizations to manage their IT infrastructure.
Technical details
This is a SQL injection vulnerability in Veeam ONE that allows a low-privileged authenticated user to inject arbitrary SQL commands through a network-accessible interface. The vulnerability requires user authentication but does not require any special privileges or user interaction to trigger. A successful exploit enables an attacker to extract confidential data from the product's database, read sensitive information, and potentially modify database records. The vulnerability was patched in Veeam ONE 13.1 (build 13.1.0.7034), Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159), and Veeam ONE 12.3 Patch 1 (build 12.3.0.7165).
Affected products
- Veeam ONE 12.x through 13.0.2.6723
Timeline
- 2026-08-04: disclosed
- 2026-08-04: patched: Veeam ONE 13.1, 13.0.2 Patch 1, and 12.3 Patch 1 released