Critical severity9.0NVD Advisory· Published Jan 8, 2026· Updated Jun 17, 2026
CVE-2025-59470
CVE-2025-59470
Description
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*range: >=13.0.0.4967,<13.0.1.1071
- Veeam/Backup and Recoveryv5Range: 13.0.0
Patches
Vulnerability mechanics
References
1- www.veeam.com/kb4792nvdVendor Advisory
News mentions
0No linked articles in our index yet.