Description
A vulnerability allowing local privilege escalation to the Reporter service context.
Published: 2026-08-04
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Veeam ONE permits an attacker with local access to gain the privileges of the Reporter service, allowing the execution of arbitrary code or actions with privileges beyond those of the initiating user. This vulnerability is identified as CWE-269, which indicates a weakness in access control that can be exploited to elevate privileges. The impact is a loss of confidentiality, integrity, and availability for the affected system, as the attacker can manipulate the service and potentially other components running under the same credentials.

Affected Systems

Veeam ONE software is affected. No specific version range is provided in the vendor information, so the vulnerability could apply to any currently installed instance of Veeam ONE unless a patch has been applied.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.4, indicating high severity. The EPSS score is not available, so the current exploitation probability is unknown; however, the lack of KEV listing suggests no widespread exploitation has been observed yet. It is inferred that the attack vector is local, as the description mentions a local privilege escalation. Exploitation would require an attacker to already have some level of local access or be able to bring a malicious payload to the target system.

Generated by OpenCVE AI on August 4, 2026 at 19:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest Veeam ONE patch once it becomes available
  • Restrict user permissions so that only trusted accounts can interact with the Reporter service
  • Disable or isolate the Reporter service if it is not required for operations

Generated by OpenCVE AI on August 4, 2026 at 19:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Reporter Service in Veeam ONE

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam one
Vendors & Products Veeam
Veeam one

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability allowing local privilege escalation to the Reporter service context.
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-08-05T03:57:14.729Z

Reserved: 2026-07-20T15:00:00.696Z

Link: CVE-2026-64634

cve-icon Vulnrichment

Updated: 2026-08-04T17:20:18.230Z

cve-icon NVD

Status : Received

Published: 2026-08-04T17:16:58.347

Modified: 2026-08-05T05:17:06.107

Link: CVE-2026-64634

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management