Description
A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
Published: 2026-08-04
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged user can retrieve report data outside the permissions granted by a shared report link. The flaw permits selective disclosure of report information beyond its intended scope, potentially exposing confidential operational data. This weakness corresponds to CWE‑863, which describes select data disclosure vulnerabilities.

Affected Systems

The vulnerability affects the Veeam ONE product. No specific versions are listed in the available information, so all deployments of Veeam ONE may be affected until a patch is applied.

Risk and Exploitability

With a CVSS score of 5.3 the issue is moderate in severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or internal, requiring only low‑privileged access to the system or the shared report link. Because the exploit does not require elevated privileges, an adversary within the network could exploit it to exfiltrate report data beyond the authorized scope.

Generated by OpenCVE AI on August 4, 2026 at 19:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Veeam ONE update that addresses the out‑of‑scope report access issue (refer to the official KB article).
  • Restrict users who can create or share report links to the minimum set of roles that require that capability.
  • Configure shared report link settings to enforce strict access boundaries and audit link usage.
  • If a patch is unavailable, isolate the Veeam ONE service behind a network segment that limits exposure to trusted users only.

Generated by OpenCVE AI on August 4, 2026 at 19:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑scope Report Data Retrieval in Veeam ONE

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam one
Vendors & Products Veeam
Veeam one

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-08-04T17:19:08.178Z

Reserved: 2026-07-20T15:00:00.696Z

Link: CVE-2026-64630

cve-icon Vulnrichment

Updated: 2026-08-04T17:19:00.483Z

cve-icon NVD

Status : Received

Published: 2026-08-04T17:16:57.963

Modified: 2026-08-04T18:16:56.177

Link: CVE-2026-64630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:45:03Z

Weaknesses