← Vulnerability feed

Vulnerability record · CVE-2023-27532 · published 10 March 2023

CVE-2023-27532: Veeam Backup & Replication missing authentication exposes stored credentials

Veeam · Veeam Backup \& Replication

Veeam Backup & Replication contains a missing authentication flaw in a critical function that allows encrypted credentials stored in the configuration database to be obtained. Because those credentials protect the backup infrastructure, their exposure can lead to compromise of backup hosts.

7.5 CVSS 3.1 High CISA KEV since 22 Aug 2023 Known ransomware use EPSS 81% · top 0.4% CWE-306 · Missing authentication for critical function
7.5CVSS 3.1 base score
81%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and requires no authentication or user interaction over the network.

What it is

Veeam Backup & Replication contains a missing authentication flaw in a critical function that allows encrypted credentials stored in the configuration database to be obtained. Because those credentials protect the backup infrastructure, their exposure can lead to compromise of backup hosts.

Impact

An attacker can retrieve encrypted credentials from the configuration database and use them to reach backup infrastructure hosts. This can enable further access to systems that hold or manage backups.

Attack surface

The CVSS vector is network-reachable with no privileges and no user interaction required. The flaw is in the Cloud Connect component per CISA's KEV entry, and the missing authentication means no valid account is needed to reach the vulnerable function.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2023-08-22 with known ransomware campaign use, and EPSS shows a 30-day probability of 0.7761 (99.5th percentile), indicating active exploitation is expected.

What to do

  • Apply the vendor fix from Veeam KB4424 immediately; if patching is not possible, follow the vendor's mitigation guidance or discontinue use of the affected component.
  • Restrict network access to Veeam Cloud Connect and backup infrastructure ports to trusted management networks only.
  • Rotate credentials stored in the Veeam configuration database and any credentials used by backup infrastructure hosts after patching.
  • Monitor for and investigate any unexpected access to backup infrastructure hosts, treating it as potential lateral movement.

Detection

  • Hunt for unusual network connections to Veeam Cloud Connect or backup server ports from hosts that do not normally manage backups.
  • Review Veeam and host logs for credential access or configuration database reads outside normal backup operations.
  • Correlate backup infrastructure host logons with known administrative accounts and alert on new or unexpected source hosts.
  • Use the CISA KEV entry and vendor advisory to confirm affected deployments and verify patch status across all Veeam Backup & Replication instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-27532 to the Known Exploited Vulnerabilities catalog on 22 August 2023 as "Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 12 September 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27532 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-40711Veeam Backup & Replication deserialization flaw allows unauthenticated RCEVeeam Backup & Replication contains a deserialization of untrusted data vulnerability (CWE-502) that permits an unauthenticated attacker to execute a…KEVEPSS 90%analysed9.8CVE-2022-26501Veeam Backup & Replication missing authentication allows remote code executionVeeam Backup & Replication 10.x and 11.x contains an incorrect access control flaw (CWE-306, missing authentication for a critical function). A remot…KEVEPSS 4.1%analysed8.8CVE-2022-26500Veeam Backup & Replication path traversal leads to remote code executionVeeam Backup & Replication 9.5U3, 9.5U4, 10.x and 11.x fail to properly limit path names, letting an authenticated remote user reach internal API fun…KEVEPSS 5.8%analysed9.9CVE-2026-21708Veeam backup \& replication sql injection vulnerabilityA vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.EPSS 1.1%9.9CVE-2026-21669Veeam backup \& replication code injection vulnerabilityA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.EPSS 1.2%9.9CVE-2025-48983Veeam backup \& replication improper access control vulnerabilityA vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts b…EPSS 0.82%9.8CVE-2025-55125Veeam backup \& replication command injection vulnerabilityThis vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.EPSS 0.88%9.8CVE-2024-29849Veeam backup \& replication improper authentication vulnerabilityVeeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.EPSS 38%

Source: NIST National Vulnerability Database (record CVE-2023-27532), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.