Veeam Backup & Replication Remote Code Execution Vulnerability – CVE-2022-26500 | CVE-2022-26501
December 28, 2022

Release Date – Dec 13, 2022
CVE Details – CVE-2022-26500 | CVE-2022-26501
Alert Severity – Critical
Affected Products – Veeam Backup & Replication | 9.5 | 10 | 11
Description –
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.
Mitigation/Solution –
Apply the patches available from VEEAM.
All new deployments of Veeam Backup & Replication version 11a and 10a installed using the ISO images dated 20220302 or later are not vulnerable.