CVE-2025-59470: 
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

CVE-2025-59470 is a command injection vulnerability in Veeam Backup & Replication that allows an authenticated Backup Operator to perform remote code execution (RCE) as the PostgreSQL (postgres) user by sending a malicious interval or order parameter. It affects Veeam Backup & Replication versions 13.0.0.4967 through 13.0.0.1070 (i.e., all v13 builds prior to 13.0.1.1071). The CVE was published on January 8, 2026, and assigned by HackerOne. It carries a CVSS v3.1 base score of 9.0 (Critical) (Veeam KB4792, NVD).

Technical details

The root cause is improper neutralization of special elements used in a command (CWE-77 — Command Injection). The vulnerability exists in the handling of the interval or order parameters within Veeam Backup & Replication's backend, where user-supplied input is passed unsanitized to a command or query executed in the context of the PostgreSQL service account. An attacker with Backup Operator role privileges can craft a malicious parameter value that injects arbitrary OS-level commands, which are then executed as the postgres user without requiring any user interaction. The attack is network-accessible (AV:N), low complexity (AC:L), and has a changed scope (S:C), meaning the impact extends beyond the vulnerable component itself (Veeam KB4792, NVD).

Impact

Successful exploitation grants an attacker arbitrary code execution as the postgres operating system user on the Veeam Backup & Replication server, resulting in HIGH confidentiality and HIGH integrity impact, with LOW availability impact. This can lead to complete compromise of the PostgreSQL database — including theft or manipulation of backup metadata and credentials — and potential lateral movement within the broader infrastructure, given that backup servers typically hold privileged access to many systems (Veeam KB4792, BleepingComputer, SecurityAffairs).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability requires the attacker to hold Backup Operator privileges, which limits the attack surface compared to unauthenticated flaws. The EPSS score is approximately 0.297%, indicating a low but non-negligible probability of exploitation in the near term. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Veeam products have historically been targeted by ransomware operators, and security researchers have noted heightened ransomware interest in Veeam vulnerabilities (UnderCodeNews, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible Veeam Backup & Replication v13 instances (versions 13.0.0.4967–13.0.0.1070) using network scanning tools such as Nmap or Shodan, or by querying internal asset inventories.
  2. Obtain Backup Operator credentials: Acquire valid credentials for an account with the Backup Operator role through phishing, credential stuffing, or lateral movement from a previously compromised host.
  3. Authenticate to Veeam: Log in to the Veeam Backup & Replication management interface or API endpoint using the obtained Backup Operator credentials.
  4. Craft malicious payload: Construct a request containing a malicious interval or order parameter value that embeds OS command injection syntax (e.g., shell metacharacters or command separators) designed to be executed by the PostgreSQL service account.
  5. Send the malicious request: Submit the crafted request to the vulnerable Veeam API or management endpoint. The unsanitized parameter is passed to a backend command or query executed as the postgres OS user.
  6. Achieve code execution: The injected command executes on the server as the postgres user, enabling the attacker to exfiltrate database contents, drop a reverse shell, create new privileged accounts, or pivot to other systems accessible from the backup server (Veeam KB4792, NVD).

Indicators of compromise

  • Network: Unexpected outbound connections from the Veeam Backup & Replication server to external or unusual internal IP addresses, particularly originating from the PostgreSQL service process.
  • Logs: Veeam service logs or PostgreSQL logs showing anomalous or malformed interval or order parameter values in API requests; unexpected SQL or OS command execution errors in Veeam or PostgreSQL logs.
  • Process: Unusual child processes spawned by the PostgreSQL service (e.g., cmd.exe, powershell.exe, bash, sh, curl, wget, net.exe) that are not part of normal database operations.
  • File System: New or modified files in the Veeam installation directory or PostgreSQL data directory, including unexpected scripts, executables, or web shells; new scheduled tasks or services created under the postgres account context.
  • Authentication: Unexpected logins or privilege escalation events associated with Backup Operator accounts, particularly outside of normal business hours (BleepingComputer, Veeam KB4792).

Mitigation and workarounds

Veeam has released a patch in version 13.0.1.1071, which resolves CVE-2025-59470 along with other security issues. All organizations running Veeam Backup & Replication versions 13.0.0.4967 through 13.0.0.1070 should upgrade to 13.0.1.1071 or later immediately. As interim mitigations, restrict network access to Veeam management interfaces to trusted hosts only, and limit assignment of the Backup Operator role to the minimum necessary personnel. Monitor for suspicious activity from Backup Operator accounts, particularly any commands executed as the postgres user (Veeam KB4792, Feedly).

Community reactions

The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, SecurityAffairs, CyberScoop, and The Register, all highlighting the critical CVSS 9.0 score and the risk to backup infrastructure (BleepingComputer, The Hacker News). Security researchers on Mastodon and Infosec.exchange flagged the vulnerability shortly after disclosure, noting the elevated risk given Veeam's historical targeting by ransomware groups. The Belgian Centre for Cybersecurity (CCB) and the Australian WA SOC both issued advisories urging immediate patching (CCB Advisory, WA SOC). Community discussion on Reddit and LinkedIn emphasized the urgency of patching given ransomware actors' known interest in Veeam environments.

Additional resources


Source: This report was generated using AI

Related Veeam Backup & Replication vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44963CRITICAL9.4
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesJun 09, 2026
CVE-2026-32997HIGH8.6
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-32996HIGH7.3
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-58070MEDIUM6.8
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesAug 26, 2026
CVE-2026-21709MEDIUM6.7
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesApr 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management