CVE-2025-55125: 
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

CVE-2025-55125 is a command injection vulnerability in Veeam Backup & Replication that allows an authenticated Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file. It affects versions 13.0.0.4967 through 13.0.1.1071 (exclusive) of Veeam Backup & Replication. The CVE was published on January 8, 2026, via HackerOne, with NVD initial analysis completed on January 12, 2026. NVD assigned a CVSS v3.1 base score of 9.8 (Critical), while the CNA (HackerOne) scored it 7.8 (High) reflecting a local attack vector (Veeam KB4792, RedHat Advisory).

Technical details

The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — Command Injection). An authenticated Backup or Tape Operator can craft a malicious backup configuration file containing injected shell commands, which are subsequently executed by the Veeam service with root privileges. The attack requires network access and valid operator-level credentials, but no user interaction beyond the attacker's own actions. No public proof-of-concept code has been identified at this time (Veeam KB4792, RedHat Advisory).

Impact

Successful exploitation grants the attacker root-level code execution on the affected Veeam Backup & Replication server, resulting in complete compromise of confidentiality, integrity, and availability. An attacker with operator credentials could exfiltrate backup data (which may contain sensitive enterprise information), tamper with or destroy backup jobs, and use the compromised server as a pivot point for lateral movement within the network. Given that Veeam servers typically hold credentials and data for a wide range of enterprise systems, the blast radius of a successful attack is significant (Veeam KB4792, BleepingComputer).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.186%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Veeam products have historically been targeted by ransomware operators, and the ransomware community has shown interest in these newly disclosed flaws (UnderCodeNews, Purple-Ops).

Exploitation steps

  1. Reconnaissance: Identify Veeam Backup & Replication servers running versions 13.0.0.4967 through 13.0.1.1071 using network scanning tools (e.g., Nmap, Shodan) targeting Veeam's default management ports.
  2. Credential Acquisition: Obtain valid Backup Operator or Tape Operator credentials through phishing, credential stuffing, or lateral movement from a previously compromised host.
  3. Craft Malicious Configuration File: Create a backup configuration file containing injected shell commands (e.g., appending command separators and arbitrary OS commands into configuration fields that are later passed unsanitized to a system shell).
  4. Submit Configuration: Use the Veeam management console or API to import or apply the malicious backup configuration file under the operator account.
  5. Achieve Root RCE: The Veeam service processes the configuration file and executes the injected commands as root, enabling the attacker to establish a reverse shell, create a privileged backdoor, exfiltrate backup data, or deploy ransomware (Veeam KB4792, BleepingComputer).

Indicators of compromise

  • Logs: Veeam audit logs showing backup configuration file creation or import events by Backup Operator or Tape Operator accounts, especially outside of normal maintenance windows; unexpected errors or exceptions in Veeam service logs related to configuration processing.
  • Process: Unusual child processes spawned by the Veeam service (e.g., cmd.exe, powershell.exe, /bin/bash, curl, wget) with operator-level or SYSTEM/root context.
  • Network: Unexpected outbound connections from the Veeam server to external IPs or internal hosts not typically accessed by the backup service; reverse shell traffic on non-standard ports.
  • File System: New or modified scripts, executables, or scheduled tasks in Veeam installation directories or system directories created around the time of suspicious configuration changes; presence of web shells or persistence mechanisms on the Veeam server.
  • Authentication: Logins by Backup Operator or Tape Operator accounts at unusual times or from unfamiliar source IPs (BleepingComputer, Veeam KB4792).

Mitigation and workarounds

Veeam has released a patch in version 13.0.1.1071, which resolves CVE-2025-55125. All users running Veeam Backup & Replication versions 13.0.0.4967 through 13.0.1.1071 should upgrade immediately. As interim mitigations, organizations should restrict Backup Operator and Tape Operator role assignments to only fully trusted personnel, monitor backup configuration file creation and modification events for anomalies, and review audit logs for unauthorized configuration changes. No configuration-only workaround has been published by Veeam (Veeam KB4792, RedHat Advisory).

Community reactions

The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, Security Affairs, and GBHackers shortly after disclosure in early January 2026 (BleepingComputer, The Hacker News, Security Affairs). Security researchers and community members on Mastodon and Bluesky highlighted the risk, particularly given Veeam's history as a ransomware target. The Belgian Centre for Cybersecurity (CCB) issued a warning about the vulnerabilities, and H-ISAC published a TLP:WHITE vulnerability bulletin for healthcare sector organizations (CCB Belgium, H-ISAC). Threat intelligence blogs noted heightened ransomware actor interest in the newly disclosed Veeam flaws (UnderCodeNews).

Additional resources


Source: This report was generated using AI

Related Veeam Backup & Replication vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44963CRITICAL9.4
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesJun 09, 2026
CVE-2026-32997HIGH8.6
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-32996HIGH7.3
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-58070MEDIUM6.8
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesAug 26, 2026
CVE-2026-21709MEDIUM6.7
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesApr 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management