CVE-2022-26501
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
Veeam Backup & Replication versions 10 and 11 have a flaw that allows improper access control, meaning unauthorized users may gain access to sensitive backup data and functions they shouldn't have. This is critical because backups often contain your most valuable data.
Veeam Backup & Replication 10.x and 11.x contain an access control bypass vulnerability (CWE-306) that enables unauthenticated or low-privileged attackers to gain unauthorized access to restricted backup operations and data. The vulnerability requires network access to the Veeam service but no special preconditions, resulting in potential complete compromise of backup integrity and confidentiality.
The full analysis of this CVE is available in Portuguese →