CVE-2022-26501criticalunder attackransomwareCWE-306

CVE-2022-26501

Published · Updated

78Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 9.8epss 4.1%
from disclosure to weapon27 days
Published on NVDMar 17
1st PoC+27d
CISA KEV+271d
exploitation probability
4.1%top 10% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2023-01-03

Apply updates per vendor instructions.

In short

Veeam Backup & Replication versions 10 and 11 have a flaw that allows improper access control, meaning unauthorized users may gain access to sensitive backup data and functions they shouldn't have. This is critical because backups often contain your most valuable data.

Technical detail

Veeam Backup & Replication 10.x and 11.x contain an access control bypass vulnerability (CWE-306) that enables unauthenticated or low-privileged attackers to gain unauthorized access to restricted backup operations and data. The vulnerability requires network access to the Veeam service but no special preconditions, resulting in potential complete compromise of backup integrity and confidentiality.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.