Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN824 _____________________________________________________________________ DATE : 05/08/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Veeam ONE versions prior to 13.1.0.7034, Veeam Service Provider Console versions prior to 9.3.0.35057. ===================================================================== https://www.veeam.com/kb4892 https://www.veeam.com/kb4893 _____________________________________________________________________ Vulnerabilities Resolved in Veeam ONE 13.1 KB ID: 4892 Product: Veeam ONE | 13 Published: 2026-08-04 Last Modified: 2026-08-05 All vulnerabilities documented in this article were resolved in Veeam ONE 13.1.0.7034. Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Issue Details All vulnerabilities disclosed in this article affect Veeam ONE 13.0.2.6723 and all earlier version 13 builds. CVE-2026-64633 A vulnerability allowing remote unauthenticated code execution on the agent host. Severity: Critical CVSS v4.0 Score: 10.0 Source: Reported through HackerOne. CVE-2026-58075 A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged to escalate privileges locally. Severity: High CVSS v4.0 Score: 8.7 Source: Reported through HackerOne. CVE-2026-58074 A vulnerability allowing a high-privileged user to execute arbitrary code on the server. Severity: High CVSS v4.0 Score: 8.6 Source: Discovered during internal testing. CVE-2026-64631 A vulnerability allowing a low-privileged user to inject SQL and extract database contents. Severity: High CVSS v4.0 Score: 8.6 Source: Reported through HackerOne. CVE-2026-64634 A vulnerability allowing local privilege escalation to the Reporter service context. Severity: High CVSS v4.0 Score: 8.4 Source: Reported through HackerOne. CVE-2026-64630 A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. Severity: Medium CVSS v4.0 Score: 5.3 Source: Reported through HackerOne. Solution These vulnerabilities were fixed starting with the following build: Veeam ONE 13.1.0.7034 If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter. _____________________________________________________________________ Vulnerabilities Resolved in Veeam Service Provider Console 9.3 KB ID: 4893 Product: Veeam Service Provider Console | 9 | 9.1 | 9.2 Published: 2026-08-04 Last Modified: 2026-08-05 All vulnerabilities documented in this article were resolved in Veeam Service Provider Console 9.3.0.35057. Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Issue Details All vulnerabilities disclosed in this article affect Veeam Service Provider Console 9.2.1.33875 and all earlier version 9 builds. CVE-2026-58073 A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. Severity: Critical CVSS v4.0 Score: 9.5 Source: Reported through HackerOne. CVE-2026-58072 A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remote code execution. Severity: Critical CVSS v4.0 Score: 9.0 Source: Reported through HackerOne. CVE-2026-58067 A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause a denial of service. Severity: High CVSS v4.0 Score: 8.7 Source: Discovered during internal testing. CVE-2026-58071 A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API as Portal Administrator during a short window after an administrator session begins. Severity: High CVSS v4.0 Score: 8.2 Source: Discovered during internal testing. Solution These vulnerabilities were fixed starting with the following build: Veeam Service Provider Console 9.3.0.35057 If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter. ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================