Veeam issues patch to close critical remote code execution flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-59470 | This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. NVD description · AI analysis pending | 9.0 | 2% |
| — |
Full article566 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The vulnerability could let operator-level users run commands as database administrator.
Listen to this article
0:00
Learn more.
Veeam has released an update to fix a security flaw in its Backup & Replication software that could let certain users run code on affected systems.
The main issue, tracked as CVE-2025-59470, affects all Veeam Backup & Replication version 13 builds, according to a security advisory released Tuesday. Veeam said older product lines, including 12.x and earlier, are not affected by the vulnerabilities listed.
Veeam said the flaw could allow someone with the “Backup Operator” or “Tape Operator” role to carry out remote code execution by sending a malicious “interval” or “order” setting. The company said that would let the attacker run commands as the “postgres” user, the account used by the product’s database.
The vulnerability has a CVSS score of 9.0, which is typically labeled “critical.” Veeam, however, said it is treating the flaw as high severity because it can only be used by someone who already has one of those operator roles.
“The Backup and Tape Operator roles are considered highly privileged roles and should be protected as such,” Veeam said in the advisory. The company added that following its security guidelines can reduce the chance of the issue being exploited.
Veeam’s documentation describes the permissions tied to those roles. A Backup Operator can start and stop existing backup jobs and export or copy backups, including creating VeeamZip backups. A Tape Operator can run tape backup and tape catalog jobs, eject tapes, import and export tapes, move tapes between media pools, copy or erase tapes and set a tape password.
Veeam said the flaw was found during internal testing. The advisory does not say if the company has seen it being used in attacks.
Veeam said the update also patches other vulnerabilities, but CVE-2025-59470 is the only one with a “critical” score.
Veeam Backup & Replication is used by organizations to make copies of important data and applications so they can be restored after cyberattacks, hardware failures or other disruptions.
The full advisory can be found on Veeam’s website.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/veeam-backup-replication-security-flaw-remote-code-execution-fix/