Executive brief
Veeam ONE is a monitoring and reporting platform for virtualized infrastructures. A vulnerability allows a user with basic network access to capture the NTLM credentials of the Reporter service account, potentially enabling unauthorized access to sensitive monitoring data and system operations.
Technical details
This is a credential capture vulnerability affecting the Reporter service in Veeam ONE. A low-privileged, authenticated user on the network can exploit this flaw to extract NTLM credentials through the affected service. The vulnerability requires network access and low-level authentication privileges but does not require user interaction. Successful exploitation allows an attacker to obtain valid credentials for the Reporter service account, which can be leveraged for lateral movement or privilege escalation. Patches are available in Veeam ONE 13.1 (build 13.1.0.7034), 13.0.2 Patch 1 (build 13.0.2.7159), and 12.3 Patch 1 (build 12.3.0.7165).
Affected products
- Veeam ONE 13.0.2.6723 and all earlier version 13 builds, 12.3.0.4670 and all earlier version 12 builds
Timeline
- 2026-08-26: disclosed
- 2026-08-04: patched: Patch available in Veeam ONE 13.1 (build 13.1.0.7034), 13.0.2 Patch 1 (build 13.0.2.7159), and 12.3 Patch 1 (build 12.3.0.7165)