Impact
A low‑privileged user can retrieve report data outside the permissions granted by a shared report link. The flaw permits selective disclosure of report information beyond its intended scope, potentially exposing confidential operational data. This weakness corresponds to CWE‑863, which describes select data disclosure vulnerabilities.
Affected Systems
The vulnerability affects the Veeam ONE product. No specific versions are listed in the available information, so all deployments of Veeam ONE may be affected until a patch is applied.
Risk and Exploitability
With a CVSS score of 5.3 the issue is moderate in severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or internal, requiring only low‑privileged access to the system or the shared report link. Because the exploit does not require elevated privileges, an adversary within the network could exploit it to exfiltrate report data beyond the authorized scope.
OpenCVE Enrichment