
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59469 is a privilege escalation vulnerability in Veeam Backup & Replication that allows an authenticated Backup or Tape Operator to write arbitrary files with root privileges. It affects versions 13.0.0.4967 through 13.0.1.1071 (exclusive) of Veeam Backup & Replication. The vulnerability was reported via HackerOne and published on January 8, 2026, with a patch released on January 14, 2026. It carries a CVSS v3.1 base score of 9.0 (Critical), assigned by HackerOne (Veeam KB4792, NVD).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), reflecting improper access control that permits lower-privileged operator roles to perform file write operations at the root level (NVD). The attack vector is network-based, requires no user interaction, and exploits the elevated trust granted to Backup or Tape Operator roles within Veeam's backup infrastructure. The scope is changed (S:C), meaning the vulnerability's impact extends beyond the vulnerable component itself, enabling an attacker to affect the underlying host system. No public proof-of-concept or detailed technical write-up has been disclosed as of the time of reporting (Feedly).
An authenticated Backup or Tape Operator can exploit this vulnerability to write arbitrary files with root privileges on the affected system, enabling modification of critical system files, injection of malicious code, and potential full system compromise. The high confidentiality and integrity impact means sensitive backup data and system configurations are at risk of exposure or tampering. Given that Veeam Backup & Replication is commonly deployed as a central backup hub with broad access to enterprise infrastructure, successful exploitation could facilitate lateral movement and compromise of connected systems (Feedly, Veeam KB4792).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.038%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to already hold a Backup or Tape Operator role, which limits the attack surface but does not eliminate risk in environments with broad role assignments or compromised operator credentials.
/var/log/auth.log) showing privilege changes./etc/cron.d/, /root/.ssh/authorized_keys, /etc/sudoers.d/) with timestamps correlating to Veeam operator activity; unexpected scripts or binaries in system directories.Veeam has released a patch in version 13.0.1.1071 of Veeam Backup & Replication; all installations running versions 13.0.0.4967 through 13.0.1.1070 should be updated immediately (Veeam KB4792). As interim mitigations, organizations should restrict Backup and Tape Operator role assignments to only fully trusted personnel, implement network segmentation to limit operator access to the backup server, and audit existing operator privileges and access logs for unauthorized activity. Monitoring for suspicious file write operations from operator accounts is also recommended until patching is complete (Feedly).
The vulnerability received broad coverage from security media outlets including The Hacker News, Security Affairs, CyberSecurityNews, and GBHackers, primarily in the context of a batch of critical Veeam vulnerabilities patched simultaneously (The Hacker News, Security Affairs). Government and sector bodies including Belgium's CCB and H-ISAC issued advisories urging prompt patching of affected Veeam installations. Community discussion on Mastodon and Bluesky highlighted the risk to backup infrastructure, with researchers noting the potential for ransomware actors to target Veeam environments. Heise and Network World also covered the story, emphasizing the risk of remote code execution and malicious backup configuration file creation (Heise).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."