
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59470 is a command injection vulnerability in Veeam Backup & Replication that allows an authenticated Backup Operator to perform remote code execution (RCE) as the PostgreSQL (postgres) user by sending a malicious interval or order parameter. It affects Veeam Backup & Replication versions 13.0.0.4967 through 13.0.0.1070 (i.e., all v13 builds prior to 13.0.1.1071). The CVE was published on January 8, 2026, and assigned by HackerOne. It carries a CVSS v3.1 base score of 9.0 (Critical) (Veeam KB4792, NVD).
The root cause is improper neutralization of special elements used in a command (CWE-77 — Command Injection). The vulnerability exists in the handling of the interval or order parameters within Veeam Backup & Replication's backend, where user-supplied input is passed unsanitized to a command or query executed in the context of the PostgreSQL service account. An attacker with Backup Operator role privileges can craft a malicious parameter value that injects arbitrary OS-level commands, which are then executed as the postgres user without requiring any user interaction. The attack is network-accessible (AV:N), low complexity (AC:L), and has a changed scope (S:C), meaning the impact extends beyond the vulnerable component itself (Veeam KB4792, NVD).
Successful exploitation grants an attacker arbitrary code execution as the postgres operating system user on the Veeam Backup & Replication server, resulting in HIGH confidentiality and HIGH integrity impact, with LOW availability impact. This can lead to complete compromise of the PostgreSQL database — including theft or manipulation of backup metadata and credentials — and potential lateral movement within the broader infrastructure, given that backup servers typically hold privileged access to many systems (Veeam KB4792, BleepingComputer, SecurityAffairs).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability requires the attacker to hold Backup Operator privileges, which limits the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.297%, indicating a low but non-negligible probability of exploitation in the near term. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Veeam products have historically been targeted by ransomware operators, and security researchers have noted heightened ransomware interest in Veeam vulnerabilities (UnderCodeNews, Feedly).
interval or order parameter value that embeds OS command injection syntax (e.g., shell metacharacters or command separators) designed to be executed by the PostgreSQL service account.postgres OS user.postgres user, enabling the attacker to exfiltrate database contents, drop a reverse shell, create new privileged accounts, or pivot to other systems accessible from the backup server (Veeam KB4792, NVD).interval or order parameter values in API requests; unexpected SQL or OS command execution errors in Veeam or PostgreSQL logs.cmd.exe, powershell.exe, bash, sh, curl, wget, net.exe) that are not part of normal database operations.postgres account context.Veeam has released a patch in version 13.0.1.1071, which resolves CVE-2025-59470 along with other security issues. All organizations running Veeam Backup & Replication versions 13.0.0.4967 through 13.0.0.1070 should upgrade to 13.0.1.1071 or later immediately. As interim mitigations, restrict network access to Veeam management interfaces to trusted hosts only, and limit assignment of the Backup Operator role to the minimum necessary personnel. Monitor for suspicious activity from Backup Operator accounts, particularly any commands executed as the postgres user (Veeam KB4792, Feedly).
The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, SecurityAffairs, CyberScoop, and The Register, all highlighting the critical CVSS 9.0 score and the risk to backup infrastructure (BleepingComputer, The Hacker News). Security researchers on Mastodon and Infosec.exchange flagged the vulnerability shortly after disclosure, noting the elevated risk given Veeam's historical targeting by ransomware groups. The Belgian Centre for Cybersecurity (CCB) and the Australian WA SOC both issued advisories urging immediate patching (CCB Advisory, WA SOC). Community discussion on Reddit and LinkedIn emphasized the urgency of patching given ransomware actors' known interest in Veeam environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."