This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious
backup configuration file.

Subscriptions

Vendors Products
Veeam Backup \& Replication Subscribe

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Mon, 12 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Veeam veeam Backup \& Replication
CPEs cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*
Vendors & Products Veeam veeam Backup \& Replication

Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam backup
Veeam veeam
Vendors & Products Veeam
Veeam backup
Veeam veeam

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Description This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-01-08T17:33:26.470Z

Reserved: 2025-08-07T15:00:05.576Z

Link: CVE-2025-55125

cve-icon Vulnrichment

Updated: 2026-01-08T17:33:22.444Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-08T17:15:47.730

Modified: 2026-01-12T16:44:01.677

Link: CVE-2025-55125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-09T13:24:54Z

Weaknesses