← Back

CVE-2022-26500

nvd nist
Published: Mar 17, 2022Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

Affected (10)

1 product
Veeam Backup & Replication
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Veeam
From 10.0.0.4442 to 10.0.1.4854
From 11.0.0.825 to 11.0.1.1261
Version 10.0.1.4854
Version 10.0.1.4854 p20201202
Version 10.0.1.4854 p20210609
Version 11.0.1.1261
Version 11.0.1.1261 p20211123
Version 11.0.1.1261 p20211211
Version 9.5.0.1536
Version 9.5.4.2615

References (5)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.