
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55125 is a command injection vulnerability in Veeam Backup & Replication that allows an authenticated Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file. It affects versions 13.0.0.4967 through 13.0.1.1071 (exclusive) of Veeam Backup & Replication. The CVE was published on January 8, 2026, via HackerOne, with NVD initial analysis completed on January 12, 2026. NVD assigned a CVSS v3.1 base score of 9.8 (Critical), while the CNA (HackerOne) scored it 7.8 (High) reflecting a local attack vector (Veeam KB4792, RedHat Advisory).
The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — Command Injection). An authenticated Backup or Tape Operator can craft a malicious backup configuration file containing injected shell commands, which are subsequently executed by the Veeam service with root privileges. The attack requires network access and valid operator-level credentials, but no user interaction beyond the attacker's own actions. No public proof-of-concept code has been identified at this time (Veeam KB4792, RedHat Advisory).
Successful exploitation grants the attacker root-level code execution on the affected Veeam Backup & Replication server, resulting in complete compromise of confidentiality, integrity, and availability. An attacker with operator credentials could exfiltrate backup data (which may contain sensitive enterprise information), tamper with or destroy backup jobs, and use the compromised server as a pivot point for lateral movement within the network. Given that Veeam servers typically hold credentials and data for a wide range of enterprise systems, the blast radius of a successful attack is significant (Veeam KB4792, BleepingComputer).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.186%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Veeam products have historically been targeted by ransomware operators, and the ransomware community has shown interest in these newly disclosed flaws (UnderCodeNews, Purple-Ops).
cmd.exe, powershell.exe, /bin/bash, curl, wget) with operator-level or SYSTEM/root context.Veeam has released a patch in version 13.0.1.1071, which resolves CVE-2025-55125. All users running Veeam Backup & Replication versions 13.0.0.4967 through 13.0.1.1071 should upgrade immediately. As interim mitigations, organizations should restrict Backup Operator and Tape Operator role assignments to only fully trusted personnel, monitor backup configuration file creation and modification events for anomalies, and review audit logs for unauthorized configuration changes. No configuration-only workaround has been published by Veeam (Veeam KB4792, RedHat Advisory).
The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, Security Affairs, and GBHackers shortly after disclosure in early January 2026 (BleepingComputer, The Hacker News, Security Affairs). Security researchers and community members on Mastodon and Bluesky highlighted the risk, particularly given Veeam's history as a ransomware target. The Belgian Centre for Cybersecurity (CCB) issued a warning about the vulnerabilities, and H-ISAC published a TLP:WHITE vulnerability bulletin for healthcare sector organizations (CCB Belgium, H-ISAC). Threat intelligence blogs noted heightened ransomware actor interest in the newly disclosed Veeam flaws (UnderCodeNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."