Description
A vulnerability allowing remote unauthenticated code execution on the agent host.
Published: 2026-08-04
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows attackers to execute arbitrary code on the Veeam ONE agent host without authentication. This means a remote user can run any command with system privileges, leading to full compromise of the host and potentially the entire Veeam environment.

Affected Systems

Veeam ONE is the affected product. The data does not list specific versions, so all installations may be vulnerable until a pull from the vendor is applied.

Risk and Exploitability

The CVSS score is 10, indicating the highest severity. EPSS is not available and the issue is not listed in CISA KEV, but the lack of any mitigation does not lower the risk; a remote attacker only needs network reach to the agent to exploit this flaw. Given the extreme severity, it is likely to be targeted once known.

Generated by OpenCVE AI on August 4, 2026 at 19:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest Veeam ONE patch or upgrade to a fixed version as released by the vendor, ensuring the agent hosts are updated.
  • If a patch is not yet available, isolate the agent host from external networks and restrict inbound traffic to only trusted management servers.
  • Enable comprehensive logging on the agent host to capture command execution events, and monitor logs for anomalous activity that may indicate exploitation.

Generated by OpenCVE AI on August 4, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Veeam ONE Agent Remote Unauthenticated Code Execution

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam one
Vendors & Products Veeam
Veeam one

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability allowing remote unauthenticated code execution on the agent host.
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-08-05T03:57:12.447Z

Reserved: 2026-07-20T15:00:00.696Z

Link: CVE-2026-64633

cve-icon Vulnrichment

Updated: 2026-08-04T17:20:00.743Z

cve-icon NVD

Status : Received

Published: 2026-08-04T17:16:58.227

Modified: 2026-08-05T05:17:05.660

Link: CVE-2026-64633

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:00:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')