← Vulnerability feed

Vulnerability record · CVE-2022-26501 · published 17 March 2022

CVE-2022-26501: Veeam Backup & Replication missing authentication allows remote code execution

Veeam · Veeam Backup \& Replication

Veeam Backup & Replication 10.x and 11.x contains an incorrect access control flaw (CWE-306, missing authentication for a critical function). A remote, unauthenticated attacker can reach the affected function without credentials, and the vendor classifies the issue as one of two related access control problems. Because the product is a backup platform, compromise threatens both the backup data and the systems it protects.

9.8 CVSS 3.1 Critical CISA KEV since 13 Dec 2022 Known ransomware use EPSS 4.1% · top 9.6% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 10.0
4.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable flaw with full impact on a backup platform, confirmed exploited in the wild and linked to ransomware campaigns.

What it is

Veeam Backup & Replication 10.x and 11.x contains an incorrect access control flaw (CWE-306, missing authentication for a critical function). A remote, unauthenticated attacker can reach the affected function without credentials, and the vendor classifies the issue as one of two related access control problems. Because the product is a backup platform, compromise threatens both the backup data and the systems it protects.

Impact

An attacker gains full compromise of the affected service with high confidentiality, integrity and availability impact, potentially leading to remote code execution and destruction or theft of backup data.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not name the specific exposed interface or port.

Exploitation

Listed in CISA KEV with known ransomware campaign use, so exploitation in the wild is confirmed. EPSS 30-day probability is about 4.1 percent (90th percentile), and all references are vendor advisories or the KEV entry, with no public exploit details in this record.

What to do

  • Apply the vendor updates referenced in Veeam KB4288 immediately; this is the only complete fix.
  • If patching cannot be done at once, isolate backup servers from untrusted networks and restrict access to management interfaces.
  • Enforce network segmentation so backup infrastructure is not reachable from general user or internet-facing segments.
  • Verify backups are immutable or offline so a compromised backup server cannot destroy recovery copies.
  • Audit accounts and services on backup servers for unauthorized changes after any suspected exposure.

Detection

  • Monitor backup server logs for unexpected or unauthenticated access to management and service interfaces.
  • Alert on new or unusual processes, service creation, or outbound connections originating from backup servers.
  • Watch for mass deletion, encryption or modification of backup files and repository contents.
  • Correlate backup server activity with known ransomware precursor behavior such as credential dumping or lateral movement.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-26501 to the Known Exploited Vulnerabilities catalog on 13 December 2022 as "Veeam Backup & Replication Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 January 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26501 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-40711Veeam Backup & Replication deserialization flaw allows unauthenticated RCEVeeam Backup & Replication contains a deserialization of untrusted data vulnerability (CWE-502) that permits an unauthenticated attacker to execute a…KEVEPSS 90%analysed8.8CVE-2022-26500Veeam Backup & Replication path traversal leads to remote code executionVeeam Backup & Replication 9.5U3, 9.5U4, 10.x and 11.x fail to properly limit path names, letting an authenticated remote user reach internal API fun…KEVEPSS 5.8%analysed7.5CVE-2023-27532Veeam Backup & Replication missing authentication exposes stored credentialsVeeam Backup & Replication contains a missing authentication flaw in a critical function that allows encrypted credentials stored in the configuratio…KEVEPSS 81%analysed9.9CVE-2026-21708Veeam backup \& replication sql injection vulnerabilityA vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.EPSS 1.1%9.9CVE-2026-21669Veeam backup \& replication code injection vulnerabilityA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.EPSS 1.2%9.9CVE-2025-48983Veeam backup \& replication improper access control vulnerabilityA vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts b…EPSS 0.82%9.8CVE-2025-55125Veeam backup \& replication command injection vulnerabilityThis vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.EPSS 0.88%9.8CVE-2024-29849Veeam backup \& replication improper authentication vulnerabilityVeeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.EPSS 38%

Source: NIST National Vulnerability Database (record CVE-2022-26501), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.