securityonline.info 6 Oct 2026, 17:54 UTC

Veeam fixes critical flaw letting Backup Viewers run code on servers

Veeam fixes critical flaw letting Backup Viewers run code on servers

VEEAM has patched three vulnerabilities in Backup & Replication 12, the lead CVE being CVE-2025-64393, a critical remote code execution flaw. The issue arises from insecure deserialization of untrusted data received via the Mount Service, and it can be exploited by a low-privileged user with the Backup Viewer role to run arbitrary code on the Veeam Backup Server. The affected builds include 12.3.2.4854 and all earlier 12.x releases, with the fix delivered in build 12.3.2.4934, also referred to as 12.3.2 P4. The advisory indicates no confirmed exploitation in the wild and no public PoCs at the time of reporting.

Two additional flaws accompany the critical bug. CVE-2026-93026 (CVSS 6.1) allows a Backup Viewer to modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials. CVE-2025-64392 (CVSS 4.8) is a reflected XSS bug in Veeam Backup Enterprise Manager that executes a script when a logged-in user opens a crafted link. Veeam notes that version 13 is not affected.

In practical terms, organisations should upgrade to 12.3.2 P4 (build 12.3.2.4934) or move to version 13, and review who holds the Backup Viewer role to limit exposure to the most serious flaws.

View full article

Article by CyberSIXT