Vulnerabilities in VEEAM
95 resultsCVE-2024-22021MEDIUMVulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a ScoEPSS 0.4%CVE-2026-64631HIGHA vulnerability allowing a low-privileged user to inject SQL and extract database contents.EPSS 0.4%CVE-2025-55125HIGHThis vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious
backup configuraEPSS 0.4%CVE-2024-42456HIGHA vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates crEPSS 0.4%CVE-2026-58069HIGHThis vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provideEPSS 0.4%CVE-2025-64393CRITICALThis vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.EPSS 0.4%CVE-2024-45204HIGHA vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved EPSS 0.4%CVE-2024-40714HIGHAn improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitiveEPSS 0.4%CVE-2026-64630MEDIUMA vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.EPSS 0.4%CVE-2026-64632HIGHA vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.EPSS 0.4%CVE-2025-23082HIGHVeeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unaEPSS 0.3%CVE-2024-42453HIGHA vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructEPSS 0.3%CVE-2025-64392MEDIUMThis vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a craftEPSS 0.3%CVE-2026-58073CRITICALA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent'sEPSS 0.3%CVE-2024-40713HIGHA vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor AutheEPSS 0.3%CVE-2024-42021HIGHAn improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.EPSS 0.3%CVE-2026-93026MEDIUMThis vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus updEPSS 0.3%CVE-2026-64635MEDIUMImproper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attEPSS 0.3%CVE-2024-40712HIGHA path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege esEPSS 0.3%CVE-2024-42022HIGHAn incorrect permission assignment vulnerability allows an attacker to modify product configuration files.EPSS 0.3%