Veeam has released security updates for Veeam ONE 13.1 to fix multiple vulnerabilities that could allow attackers to execute code, access sensitive files, steal database data, and escalate privileges.
The most severe issue, tracked as CVE-2026-64633, has received a critical CVSS v4.0 score of 10.0 because it allows remote, unauthenticated code execution on the Veeam ONE agent host.
The vulnerabilities affects Veeam ONE 13.0.2.6723 and all earlier version 13 builds. Organizations using affected deployments should update immediately to Veeam ONE 13.1.0.7034, the version that resolves all issues listed in Veeam Knowledge Base article KB4892.
CVE-2026-64633 is the most dangerous flaw in the advisory. It could allow a remote attacker to execute arbitrary code on an exposed agent host without authentication.
A successful exploit could give threat actors a foothold in the targeted environment, potentially enabling malware deployment, lateral movement, credential theft, or ransomware activity.
Another high-severity issue, CVE-2026-58075, enables an unauthenticated attacker to read arbitrary files from the host. Attackers could use this capability to access configuration files, credentials, logs, or other sensitive data. Veeam noted that this issue could also be leveraged to support local privilege escalation.
CVE-2026-58074 affects high-privileged users and allows arbitrary code execution on the Veeam ONE server. While exploitation requires elevated access, the vulnerability could allow an insider or attacker who has already compromised a privileged account to run malicious code and expand their control over the server.
The Veeam advisory (KB4892) also addresses CVE-2026-64631, an SQL injection vulnerability that allows low-privileged users to extract database contents.
The flaw could expose infrastructure details, backup information, account data, and operational records, helping attackers map the environment and identify high-value systems.
CVE-2026-64634 allows local privilege escalation to the Reporter service context. An attacker with local access could exploit the flaw to gain additional permissions and access to functions or data available to that service.
| CVE ID | Issue | Severity |
|---|---|---|
| CVE-2026-64633 | Unauthenticated RCE | Critical |
| CVE-2026-58075 | Arbitrary file read | High |
| CVE-2026-58074 | Privileged code execution | High |
| CVE-2026-64631 | SQL injection | High |
| CVE-2026-64634 | Local privilege escalation | High |
| CVE-2026-64630 | Unauthorized report access | Medium |
Veeam also fixed CVE-2026-64630, a medium-severity vulnerability that allows low-privileged users to retrieve report data outside the intended scope of a shared report link.
Several vulnerabilities were reported through HackerOne, while CVE-2026-58074 was discovered during Veeam’s internal testing. Veeam stated that attackers often reverse-engineer patches after public disclosures to identify and target unpatched installations.
Security teams should identify all Veeam ONE version 13 deployments, confirm whether they are running builds earlier than 13.1.0.7034, and apply the available update as soon as possible.
Organizations should also review Veeam ONE server and agent exposure, restrict access to trusted administrators, monitor for suspicious activity, and investigate unusual database queries, report access, or code execution events.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…