← Vulnerability feed

Vulnerability record · CVE-2025-48983 · published 31 October 2025

CVE-2025-48983: Veeam backup \& replication improper access control vulnerability

Veeam · Veeam Backup \& Replication

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.

9.9 CVSS 3.1 Critical EPSS 0.82% · top 44.6% CWE-284 · Improper access control
9.9CVSS 3.1 base score
0.82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.veeam.com/kb4771 Vendor Advisory

Track CVE-2025-48983 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-40711Veeam Backup & Replication deserialization flaw allows unauthenticated RCEVeeam Backup & Replication contains a deserialization of untrusted data vulnerability (CWE-502) that permits an unauthenticated attacker to execute a…KEVEPSS 90%analysed9.8CVE-2022-26501Veeam Backup & Replication missing authentication allows remote code executionVeeam Backup & Replication 10.x and 11.x contains an incorrect access control flaw (CWE-306, missing authentication for a critical function). A remot…KEVEPSS 4.1%analysed8.8CVE-2022-26500Veeam Backup & Replication path traversal leads to remote code executionVeeam Backup & Replication 9.5U3, 9.5U4, 10.x and 11.x fail to properly limit path names, letting an authenticated remote user reach internal API fun…KEVEPSS 5.8%analysed7.5CVE-2023-27532Veeam Backup & Replication missing authentication exposes stored credentialsVeeam Backup & Replication contains a missing authentication flaw in a critical function that allows encrypted credentials stored in the configuratio…KEVEPSS 81%analysed9.9CVE-2026-21708Veeam backup \& replication sql injection vulnerabilityA vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.EPSS 1.1%9.9CVE-2026-21669Veeam backup \& replication code injection vulnerabilityA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.EPSS 1.2%9.8CVE-2025-55125Veeam backup \& replication command injection vulnerabilityThis vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.EPSS 0.88%9.8CVE-2024-29849Veeam backup \& replication improper authentication vulnerabilityVeeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.EPSS 38%

Source: NIST National Vulnerability Database (record CVE-2025-48983), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.