Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-58070
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

CVE-2026-58070 is a credential disclosure vulnerability in Veeam Backup and Replication that records guest OS processing credentials in cleartext within a support log file on the guest system. Any local user with read access to that log can recover privileged account credentials. The vulnerability affects Veeam Backup and Replication versions prior to 13.0.3, and a patch is available. It carries a CVSS v4.0 base score of 6.8 (Medium) (GitHub Advisory, Veeam KB4902).

Technical details

The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File): during guest OS processing operations, Veeam Backup and Replication writes privileged account credentials in plaintext to a support log stored on the guest system. The attack vector is local — an attacker must already have a low-privileged account on the guest OS with read access to the support log directory. No special attack complexity, user interaction, or additional attack requirements are needed beyond that initial local access (GitHub Advisory).

Impact

Successful exploitation allows any local user with read permissions on the support log to recover plaintext privileged account credentials used during guest OS processing. This constitutes a high confidentiality impact on the vulnerable system, with no direct integrity or availability impact. However, recovered credentials could enable privilege escalation within the guest OS or lateral movement to other systems managed by Veeam, significantly expanding the blast radius beyond the initial compromise (GitHub Advisory, Veeam KB4902).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.116% (2nd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is not automatable and requires pre-existing local access to the guest system.

Exploitation steps

  1. Gain local access: Obtain a low-privileged user account on the guest OS where Veeam Backup and Replication performs guest processing operations.
  2. Locate support log files: Identify the directory where Veeam writes support logs on the guest system (typically within Veeam's application data or temp directories).
  3. Read the log file: Open or parse the support log file using standard file read permissions — no elevated privileges are required if the log is world-readable or readable by the attacker's account.
  4. Extract credentials: Search the log contents for plaintext credential strings (usernames and passwords) recorded during guest OS processing tasks.
  5. Leverage credentials: Use the recovered privileged credentials to escalate privileges on the guest OS or authenticate to other systems managed by Veeam (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected access or reads of Veeam support log files on guest systems by non-administrative accounts; presence of log files containing credential strings in Veeam application data directories.
  • Logs: OS audit logs (e.g., Windows Security Event Log) showing low-privileged user accounts accessing Veeam support log file paths; file access events (Event ID 4663) on log directories.
  • Process: Unusual processes (e.g., findstr, grep, type, cat, or scripting interpreters) invoked by non-admin users targeting Veeam log file paths.

Mitigation and workarounds

Upgrade Veeam Backup and Replication to version 13.0.3 or later, which resolves this vulnerability (Veeam KB4902). As an interim workaround, restrict file system permissions on Veeam support log directories on guest systems so that only authorized administrative accounts have read access. Additionally, consider implementing log redaction or rotation policies to purge existing logs that may contain plaintext credentials.

Additional resources


SourceThis report was generated using AI

Related Veeam Backup & Replication vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44963CRITICAL9.4
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesJun 09, 2026
CVE-2026-32997HIGH8.6
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-32996HIGH7.3
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-58070MEDIUM6.8
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesAug 26, 2026
CVE-2026-21709MEDIUM6.7
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesApr 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management