Vulnerability record · CVE-2022-26500 · published 17 March 2022
CVE-2022-26500: Veeam Backup & Replication path traversal leads to remote code execution
Veeam · Veeam Backup \& Replication
Veeam Backup & Replication 9.5U3, 9.5U4, 10.x and 11.x fail to properly limit path names, letting an authenticated remote user reach internal API functions. That access allows the attacker to upload and execute arbitrary code on the backup server. Because backup servers hold credentials and restore points, compromise there is high value for follow-on ransomware activity.
Description
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8, CISA KEV listing with known ransomware use, and code execution on a high-value backup server make this a high-priority patch despite the authentication requirement.
What it is
Veeam Backup & Replication 9.5U3, 9.5U4, 10.x and 11.x fail to properly limit path names, letting an authenticated remote user reach internal API functions. That access allows the attacker to upload and execute arbitrary code on the backup server. Because backup servers hold credentials and restore points, compromise there is high value for follow-on ransomware activity.
Impact
An attacker with valid credentials gains code execution on the Veeam server, enabling control of backup infrastructure, access to stored credentials and potential destruction or theft of backups.
Attack surface
Reached over the network via the Veeam API; the CVSS vector shows network access with low privileges required and no user interaction. Authentication is required, so the attacker needs at least a low-privileged account.
Exploitation
Listed in CISA KEV with known ransomware campaign use and a patch deadline of 2023-01-03, indicating active exploitation. EPSS 30-day probability is about 5.8 percent (92.8th percentile), and references are vendor advisories plus the CISA KEV entry.
What to do
- Apply the vendor update per Veeam KB4288 and CISA KEV required action.
- Restrict network access to the Veeam Backup & Replication console and API to trusted management networks.
- Review and minimize accounts with access to the Veeam server; remove unused or overly privileged accounts.
- Monitor Veeam servers for unexpected process creation or file uploads and treat backup infrastructure as a high-value target.
Detection
- Alert on unexpected child processes spawned by Veeam services or the backup server.
- Monitor for anomalous file writes or uploads into Veeam application and data directories.
- Audit authentication and API activity on the Veeam server for unusual accounts or off-hours access.
- Correlate Veeam server activity with ransomware precursor behaviors such as credential access and backup deletion.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-26500 to the Known Exploited Vulnerabilities catalog on 13 December 2022 as "Veeam Backup & Replication Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 January 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://veeam.com | Vendor Advisory |
| https://www.veeam.com/kb4288 | Vendor Advisory |
| https://veeam.com | Vendor Advisory |
| https://www.veeam.com/kb4288 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26500 | US Government Resource |
Track CVE-2022-26500 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26500), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.