← Vulnerability feed

Vulnerability record · CVE-2022-26500 · published 17 March 2022

CVE-2022-26500: Veeam Backup & Replication path traversal leads to remote code execution

Veeam · Veeam Backup \& Replication

Veeam Backup & Replication 9.5U3, 9.5U4, 10.x and 11.x fail to properly limit path names, letting an authenticated remote user reach internal API functions. That access allows the attacker to upload and execute arbitrary code on the backup server. Because backup servers hold credentials and restore points, compromise there is high value for follow-on ransomware activity.

8.8 CVSS 3.1 High CISA KEV since 13 Dec 2022 Known ransomware use EPSS 5.8% · top 7.1% CWE-22 · Path traversal
8.8CVSS 3.1 base score, v2 6.5
5.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8, CISA KEV listing with known ransomware use, and code execution on a high-value backup server make this a high-priority patch despite the authentication requirement.

What it is

Veeam Backup & Replication 9.5U3, 9.5U4, 10.x and 11.x fail to properly limit path names, letting an authenticated remote user reach internal API functions. That access allows the attacker to upload and execute arbitrary code on the backup server. Because backup servers hold credentials and restore points, compromise there is high value for follow-on ransomware activity.

Impact

An attacker with valid credentials gains code execution on the Veeam server, enabling control of backup infrastructure, access to stored credentials and potential destruction or theft of backups.

Attack surface

Reached over the network via the Veeam API; the CVSS vector shows network access with low privileges required and no user interaction. Authentication is required, so the attacker needs at least a low-privileged account.

Exploitation

Listed in CISA KEV with known ransomware campaign use and a patch deadline of 2023-01-03, indicating active exploitation. EPSS 30-day probability is about 5.8 percent (92.8th percentile), and references are vendor advisories plus the CISA KEV entry.

What to do

  • Apply the vendor update per Veeam KB4288 and CISA KEV required action.
  • Restrict network access to the Veeam Backup & Replication console and API to trusted management networks.
  • Review and minimize accounts with access to the Veeam server; remove unused or overly privileged accounts.
  • Monitor Veeam servers for unexpected process creation or file uploads and treat backup infrastructure as a high-value target.

Detection

  • Alert on unexpected child processes spawned by Veeam services or the backup server.
  • Monitor for anomalous file writes or uploads into Veeam application and data directories.
  • Audit authentication and API activity on the Veeam server for unusual accounts or off-hours access.
  • Correlate Veeam server activity with ransomware precursor behaviors such as credential access and backup deletion.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-26500 to the Known Exploited Vulnerabilities catalog on 13 December 2022 as "Veeam Backup & Replication Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 January 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26500 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-40711Veeam Backup & Replication deserialization flaw allows unauthenticated RCEVeeam Backup & Replication contains a deserialization of untrusted data vulnerability (CWE-502) that permits an unauthenticated attacker to execute a…KEVEPSS 90%analysed9.8CVE-2022-26501Veeam Backup & Replication missing authentication allows remote code executionVeeam Backup & Replication 10.x and 11.x contains an incorrect access control flaw (CWE-306, missing authentication for a critical function). A remot…KEVEPSS 4.1%analysed7.5CVE-2023-27532Veeam Backup & Replication missing authentication exposes stored credentialsVeeam Backup & Replication contains a missing authentication flaw in a critical function that allows encrypted credentials stored in the configuratio…KEVEPSS 81%analysed9.9CVE-2026-21708Veeam backup \& replication sql injection vulnerabilityA vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.EPSS 1.1%9.9CVE-2026-21669Veeam backup \& replication code injection vulnerabilityA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.EPSS 1.2%9.9CVE-2025-48983Veeam backup \& replication improper access control vulnerabilityA vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts b…EPSS 0.82%9.8CVE-2025-55125Veeam backup \& replication command injection vulnerabilityThis vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.EPSS 0.88%9.8CVE-2024-29849Veeam backup \& replication improper authentication vulnerabilityVeeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.EPSS 38%

Source: NIST National Vulnerability Database (record CVE-2022-26500), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.