ZeroHour

CVE-2022-26500

KEV ransomwarelarge

Authenticated Path Traversal RCE in Veeam Backup & Replication

CISA: Veeam Backup & Replication Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
6%p93
Published
()
KEV added
AI analysis

CVE-2022-26500 is a path traversal flaw (CWE-22, improper limitation of path names) in the internal API functions of Veeam Backup & Replication versions 9.5U3, 9.5U4, 10.x, and 11.x. A remote attacker who has valid credentials can reach these internal API functions and, because file paths are not properly restricted, upload arbitrary code and have it executed on the backup server. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8), and it is known to have been leveraged as an entry point for ransomware operations, including activity associated with the Cuba ransomware gang. Any organization running one of the affected Veeam Backup & Replication versions is exposed, particularly where the backup infrastructure is reachable from the internet. The flaw is actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-12-13 with ransomware use listed as known, and EPSS estimates a 5.8% probability of exploitation in the next 30 days (93rd percentile).

What to do: Apply Veeam's updates per vendor instructions immediately, as the same advisory also addressed the related RCE CVE-2022-26501; prioritize 9.5U3/9.5U4, 10.x, and 11.x deployments. Restrict network access to the Veeam Backup & Replication API interfaces, and audit backup servers for signs of compromise (unexpected processes or accounts) given known ransomware use of this flaw. No public proof-of-concept is known, but KEV listing confirms active exploitation, so treat patching as urgent.

Affected
Veeam Backup & Replication9.5U3, 9.5U4, 10.x, 11.x
Estimated exposure
largeorder of tens of thousands of backup server deployments — Veeam Backup & Replication is one of the most widely deployed enterprise backup products (Veeam reports hundreds of thousands of customers), and because affected versions span the product's then-current release line and backup servers are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Veeam Backup & Replication
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
veeam
Products
veeam backup \& replication
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news