CVE-2022-26500
KEV ransomwarelargeAuthenticated Path Traversal RCE in Veeam Backup & Replication
CISA: Veeam Backup & Replication Remote Code Execution Vulnerability
CVE-2022-26500 is a path traversal flaw (CWE-22, improper limitation of path names) in the internal API functions of Veeam Backup & Replication versions 9.5U3, 9.5U4, 10.x, and 11.x. A remote attacker who has valid credentials can reach these internal API functions and, because file paths are not properly restricted, upload arbitrary code and have it executed on the backup server. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8), and it is known to have been leveraged as an entry point for ransomware operations, including activity associated with the Cuba ransomware gang. Any organization running one of the affected Veeam Backup & Replication versions is exposed, particularly where the backup infrastructure is reachable from the internet. The flaw is actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-12-13 with ransomware use listed as known, and EPSS estimates a 5.8% probability of exploitation in the next 30 days (93rd percentile).
What to do: Apply Veeam's updates per vendor instructions immediately, as the same advisory also addressed the related RCE CVE-2022-26501; prioritize 9.5U3/9.5U4, 10.x, and 11.x deployments. Restrict network access to the Veeam Backup & Replication API interfaces, and audit backup servers for signs of compromise (unexpected processes or accounts) given known ransomware use of this flaw. No public proof-of-concept is known, but KEV listing confirms active exploitation, so treat patching as urgent.
| Veeam Backup & Replication | 9.5U3, 9.5U4, 10.x, 11.x |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
- Affected
- Veeam Backup & Replication
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- veeam
- Products
- veeam backup \& replication
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H