Description
A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
Published: 2026-08-04
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits an unauthenticated attacker to read any files from the Veeam ONE host, enabling the attacker to view sensitive configuration data and potential credentials. Once arbitrary files are accessible, the attacker may use that information to elevate privileges locally, potentially taking full control of the system. This flaw is classified as an authentication bypass (CWE‑287) and can lead to confidentiality loss and internal privilege escalation.

Affected Systems

The vulnerability affects Veeam, specifically the Veeam ONE product. No specific version numbers are listed in the advisory, so all current installations may be at risk until an official patch is released.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity rating, with unauthenticated access providing the initial foothold. The EPSS score is not provided, but the lack of KEV listing suggests limited public exploitation to date. The likely attack vector is remote network access to the Veeam ONE service; however, any authenticated session can exploit the flaw if the authentication mechanism is bypassed. Given the high severity and potential for local privilege escalation, the vulnerability represents a significant risk to affected environments.

Generated by OpenCVE AI on August 4, 2026 at 19:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for Veeam ONE that removes the unauthenticated file disclosure and authentication bypass flaw.
  • Restrict network traffic to the Veeam ONE management interface to a known set of trusted hosts or a VPN only.
  • Disable any unused remote access services or APIs on the Veeam ONE host to reduce attack surface.

Generated by OpenCVE AI on August 4, 2026 at 19:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 05 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated File Disclosure with Potential Privilege Escalation in Veeam ONE

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam one
Vendors & Products Veeam
Veeam one

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-08-05T13:33:25.454Z

Reserved: 2026-06-28T15:00:00.720Z

Link: CVE-2026-58075

cve-icon Vulnrichment

Updated: 2026-08-04T17:19:46.283Z

cve-icon NVD

Status : Received

Published: 2026-08-04T17:16:57.190

Modified: 2026-08-05T14:17:08.230

Link: CVE-2026-58075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:45:03Z

Weaknesses