Veeam
by Veeam
CVEs (12)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65641 | Cri | 0.60 | — | 0.01 | Aug 26, 2026 | A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account. | ||
| CVE-2026-58075 | Hig | 0.57 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally. | ||
| CVE-2024-40718 | Hig | 0.57 | 8.8 | 0.00 | Sep 7, 2024 | A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability. | ||
| CVE-2026-64631 | Hig | 0.56 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing a low-privileged user to inject SQL and extract database contents. | ||
| CVE-2024-39718 | Hig | 0.53 | 8.1 | 0.01 | Sep 7, 2024 | An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account. | ||
| CVE-2024-40712 | Hig | 0.51 | 7.8 | 0.00 | Sep 7, 2024 | A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE). | ||
| CVE-2022-26503 | Hig | 0.51 | 7.8 | 0.01 | Mar 17, 2022 | Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges. | ||
| CVE-2026-58070 | Med | 0.44 | — | 0.00 | Aug 26, 2026 | A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials. | ||
| CVE-2024-42021 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2024 | An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials. | ||
| CVE-2025-24287 | Med | 0.40 | 6.1 | 0.00 | Jun 19, 2025 | A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions. | ||
| CVE-2024-42022 | Med | 0.34 | 5.3 | 0.00 | Sep 7, 2024 | An incorrect permission assignment vulnerability allows an attacker to modify product configuration files. | ||
| CVE-2024-45204 | Med | 0.28 | 4.3 | 0.00 | Dec 4, 2024 | A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial… |
- risk 0.60cvss —epss 0.01
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
- risk 0.57cvss —epss 0.00
A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
- risk 0.57cvss 8.8epss 0.00
A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.
- risk 0.56cvss —epss 0.00
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
- risk 0.53cvss 8.1epss 0.01
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
- risk 0.51cvss 7.8epss 0.00
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
- risk 0.51cvss 7.8epss 0.01
Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.
- risk 0.44cvss —epss 0.00
A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.
- risk 0.42cvss 6.5epss 0.00
An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.
- risk 0.40cvss 6.1epss 0.00
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.
- risk 0.34cvss 5.3epss 0.00
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
- risk 0.28cvss 4.3epss 0.00
A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial…