Wiz Agents & Workflows are here

CVE-2024-29849
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2024-29849) was discovered in Veeam Backup Enterprise Manager that allows unauthenticated users to log in as any user to the enterprise manager web interface. The vulnerability was disclosed on May 21, 2024, and received a Critical CVSS score of 9.8. The affected software versions include Veeam Backup Enterprise Manager versions 5.0, 6.1, 6.5, 7.0, 8.0, 9.0, 9.5, 10, 11, 12, and 12.1 (Veeam KB, Arctic Wolf).

Technical details

The vulnerability allows an unauthenticated attacker to bypass authentication measures and gain unauthorized access to the Veeam Backup Enterprise Manager web interface with the ability to log in as any user. The vulnerability has been assigned a CVSS v3.0 score of 9.8 (Critical) with the following vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The affected application is an optional add-on application used to manage Veeam Backup & Replication via a web console in Veeam environments (Arctic Wolf).

Impact

The vulnerability poses a significant security risk as it allows unauthorized access to the Veeam Backup Enterprise Manager web interface, potentially enabling attackers to gain full control over the backup system. This could lead to unauthorized access to sensitive data, manipulation of backup configurations, and disruption of backup operations (Arctic Wolf).

Mitigation and workarounds

Veeam has released version 12.1.2.172 which addresses this vulnerability. If immediate upgrading is not feasible, users can mitigate the risk by stopping and disabling the 'VeeamEnterpriseManagerSvc' and the 'VeeamRESTSvc' services. Additionally, Veeam recommends uninstalling Backup Enterprise Manager if it is not in use within the environment, as it is an optional add-on application (Veeam KB).

Additional resources


SourceThis report was generated using AI

Related Veeam Backup & Replication vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21708CRITICAL9.9
  • Veeam Backup & ReplicationVeeam Backup & Replication
  • cpe:2.3:a:veeam:backup_and_replication
NoYesMar 12, 2026
CVE-2026-21669CRITICAL9.9
  • Veeam Backup & ReplicationVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMar 12, 2026
CVE-2026-21671CRITICAL9.1
  • Veeam Backup & ReplicationVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMar 12, 2026
CVE-2026-21672HIGH8.8
  • Veeam Backup & ReplicationVeeam Backup & Replication
  • cpe:2.3:a:veeam:backup_and_replication
NoYesMar 12, 2026
CVE-2026-21670MEDIUM6.5
  • Veeam Backup & ReplicationVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMar 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management