Description
A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.
Published: 2026-07-22
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Veeam Updater component of the Veeam Software Appliance that allows an authenticated local user to elevate privileges and gain root-level access to the underlying operating system. This flaw, categorized as CWE‑22, enables an attacker who can execute code locally to bypass normal permission boundaries. The resulting root access would give full control over the appliance, potentially exposing backup data, enabling further lateral movement, and compromising overall infrastructure security.

Affected Systems

All installations of Veeam Backup and Replication that include the Updater component may be impacted; no specific version information is provided in the advisory.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access, meaning an attacker must already have some form of local presence or physical access to the appliance to launch the attack.

Generated by OpenCVE AI on August 4, 2026 at 00:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or update to Veeam Backup and Replication when it becomes available.
  • Restrict local user privileges and enforce the principle of least privilege on the appliance, limiting access to the Updater component.
  • Isolate the appliance from untrusted network segments or users until a patch is applied, reducing the opportunity for local privilege escalation.

Generated by OpenCVE AI on August 4, 2026 at 00:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Veeam Updater Component

Thu, 30 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Veeam Updater

Mon, 27 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Veeam Updater

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam backup And Replication
Vendors & Products Veeam
Veeam backup And Replication

Wed, 22 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Veeam Backup And Replication
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-22T13:02:38.298Z

Reserved: 2026-06-23T15:00:03.632Z

Link: CVE-2026-56844

cve-icon Vulnrichment

Updated: 2026-07-22T13:02:31.604Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-22T01:16:26.523

Modified: 2026-07-23T18:27:07.573

Link: CVE-2026-56844

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')