Description
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
Published: 2026-08-04
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Veeam ONE permits a user with elevated local privileges to execute arbitrary code on the server, allowing the attacker to compromise the integrity and confidentiality of the system. The vulnerability is an instance of Code Injection (CWE-94) and could be leveraged to gain full control over the affected platform.

Affected Systems

Veeam ONE is the only product identified as affected. No specific version information is provided, so any installation lacking the latest vendor fixes should be considered at risk.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation yet a potentially serious attack vector for authenticated users with high privileges. If an attacker can locally authenticate as a privileged user, the vulnerability could be readily exploited to execute malicious code.

Generated by OpenCVE AI on August 4, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent patch for Veeam ONE, as detailed in the official KB article at https://www.veeam.com/kb4892
  • Limit local privileged user access to only required accounts and enforce the principle of least privilege
  • Disable any unneeded administrative features or services that expose the vulnerable code path

Generated by OpenCVE AI on August 4, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Arbitrary Code Execution in Veeam ONE

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam one
Vendors & Products Veeam
Veeam one

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-08-05T03:57:06.591Z

Reserved: 2026-06-28T15:00:00.720Z

Link: CVE-2026-58074

cve-icon Vulnrichment

Updated: 2026-08-04T17:18:44.459Z

cve-icon NVD

Status : Received

Published: 2026-08-04T17:16:57.067

Modified: 2026-08-05T05:17:02.860

Link: CVE-2026-58074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:30:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')