Veeam Backup and Replication Vulnerability Allow Attackers to Execute Malicious Script

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Veeam has released Veeam Backup & Replication 12.3.2 P4, build 12.3.2.4934, to address four security vulnerabilities, including a flaw that lets attackers execute malicious scripts in an authenticated user’s browser.

Released on October 6, 2026, the update also fixes a critical remote code execution vulnerability affecting the backup server. The vulnerabilities carry CVSS 4.0 scores ranging from 4.8 to 9.4. They involve browser script execution, insecure deserialization, unauthorized access to sensitive configuration data, and arbitrary file reading.

Although the weaknesses have different requirements, several involve authenticated accounts with limited privileges, making account permissions an important consideration for affected deployments.

Tracked as CVE-2025-64392, the reflected cross-site scripting vulnerability affects Veeam Backup Enterprise Manager. It allows an attacker to execute a script in the browser of an authenticated portal user who opens a specially crafted link. Veeam assigned the vulnerability a medium severity rating and a CVSS score of 4.8.

The attack requires user interaction: an authenticated portal user must open the malicious link. This distinguishes the flaw from direct code execution on the backup server.

The advisory identifies Enterprise Manager build 12.3.2.4854 and earlier version 12 builds as affected, while version 13 is not affected.

Veeam Backup and Replication Vulnerability

The most severe issue, CVE-2025-64393, has a critical rating and a CVSS score of 9.4. A low-privileged user assigned the Backup Viewer role can exploit insecure deserialization of untrusted data received through the Mount Service to achieve remote code execution on the Veeam Backup Server.

This vulnerability creates a significant risk because exploitation does not require an administrator account. Veeam’s published CVSS vector also indicates that user interaction is not required. The flaw affects build 12.3.2.4854 and earlier 12.3 builds, with the fix included in build 12.3.2.4934.

CVE-2026-58069, rated high with a CVSS score of 8.3, allows an authenticated Veeam Cloud Connect tenant to read arbitrary files on the service provider host.

Unlike the three vulnerabilities described in KB4934, this issue also affects specified version 13 builds and has separate fixes for those releases.

CVE-2026-93026 carries a medium severity rating and a CVSS score of 6.1. An authenticated Backup Viewer user can modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials on the backup server.

Administrators can check their installed build through the Veeam Backup & Replication Console’s Main Menu under Help > About. Affected version 12 deployments should move to build 12.3.2.4934. Veeam warns that attackers may reverse-engineer published patches to target systems that remain unpatched.

The supplied release notes also describe fixes for Linux server readdition failures involving missing SSH credentials and Windows Agent installation or upgrade failures on Windows 7 and Windows Server 2008 R2 systems.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Veeam Backup and Replication Vulnerability Allow Attackers to Execute Malicious Script appeared first on Cyber Security News.