
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-58070 is a credential disclosure vulnerability in Veeam Backup and Replication that records guest OS processing credentials in cleartext within a support log file on the guest system. Any local user with read access to that log can recover privileged account credentials. The vulnerability affects Veeam Backup and Replication versions prior to 13.0.3, and a patch is available. It carries a CVSS v4.0 base score of 6.8 (Medium) (GitHub Advisory, Veeam KB4902).
The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File): during guest OS processing operations, Veeam Backup and Replication writes privileged account credentials in plaintext to a support log stored on the guest system. The attack vector is local — an attacker must already have a low-privileged account on the guest OS with read access to the support log directory. No special attack complexity, user interaction, or additional attack requirements are needed beyond that initial local access (GitHub Advisory).
Successful exploitation allows any local user with read permissions on the support log to recover plaintext privileged account credentials used during guest OS processing. This constitutes a high confidentiality impact on the vulnerable system, with no direct integrity or availability impact. However, recovered credentials could enable privilege escalation within the guest OS or lateral movement to other systems managed by Veeam, significantly expanding the blast radius beyond the initial compromise (GitHub Advisory, Veeam KB4902).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.116% (2nd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is not automatable and requires pre-existing local access to the guest system.
findstr, grep, type, cat, or scripting interpreters) invoked by non-admin users targeting Veeam log file paths.Upgrade Veeam Backup and Replication to version 13.0.3 or later, which resolves this vulnerability (Veeam KB4902). As an interim workaround, restrict file system permissions on Veeam support log directories on guest systems so that only authorized administrative accounts have read access. Additionally, consider implementing log redaction or rotation policies to purge existing logs that may contain plaintext credentials.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."