CVE-2022-26500 is a critical path traversal vulnerability affecting Veeam Backup & Replication versions 9.5U3, 9.5U4, 10.x, and 11.x. This flaw allows remote authenticated attackers to access internal API functions, enabling the upload and execution of arbitrary code on affected systems. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its low attack complexity and complete compromise potential (Confidentiality, Integrity, Availability). This vulnerability is actively exploited in the wild, including in known ransomware campaigns, and has garnered substantial community discussion and media coverage, despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0.4442, < 10.0.1.4854CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:* | ||
>= 11.0.0.825, < 11.0.1.1261CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:* | ||
9.5.0.1536CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:9.5.0.1536:*:*:*:*:*:*:* | ||
9.5.4.2615CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:9.5.4.2615:*:*:*:*:*:*:* | ||
10.0.1.4854CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:10.0.1.4854:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.