VYPR
High severity8.8CISA KEVNVD Advisory· Published Mar 17, 2022· Updated Jun 17, 2026

CVE-2022-26500

CVE-2022-26500

Description

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11
  • cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*range: >=10.0.0.4442,<10.0.1.4854
    • cpe:2.3:a:veeam:veeam_backup_\&_replication:10.0.1.4854:-:*:*:*:*:*:*
    • cpe:2.3:a:veeam:veeam_backup_\&_replication:10.0.1.4854:p20201202:*:*:*:*:*:*
    • cpe:2.3:a:veeam:veeam_backup_\&_replication:10.0.1.4854:p20210609:*:*:*:*:*:*
    • cpe:2.3:a:veeam:veeam_backup_\&_replication:11.0.1.1261:-:*:*:*:*:*:*
    • cpe:2.3:a:veeam:veeam_backup_\&_replication:11.0.1.1261:p20211123:*:*:*:*:*:*
    • cpe:2.3:a:veeam:veeam_backup_\&_replication:11.0.1.1261:p20211211:*:*:*:*:*:*
    • cpe:2.3:a:veeam:veeam_backup_\&_replication:9.5.0.1536:*:*:*:*:*:*:*
    • cpe:2.3:a:veeam:veeam_backup_\&_replication:9.5.4.2615:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 9.5U3, 9.5U4, 10.x, and 11.x

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.