CVE-2022-26501: Veeam Backup & Replication Remote Code Execution Vulnerability
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.
Other sources
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Stop and disable the Veeam Distribution Service on Backup & Replication servers to prevent unauthenticated access to internal APIs until a vendor fix is available.
Veeam Distribution Service (Veeam Backup & Replication) service_enabled = disabled - Compensating control
Restrict network access to the Veeam Distribution Service and Backup & Replication management ports with firewall rules/ACLs or network segmentation so only trusted administrative IPs/networks can reach the service.
- Operational
Monitor and review Backup & Replication logs for suspicious activity, investigate potential compromise, isolate affected hosts if exploitation is suspected, and rotate any credentials or secrets that may have been exposed.
Event History
Frequently Asked Questions
What is CVE-2022-26501?
CVE-2022-26501 is a remote code execution vulnerability in Veeam Backup & Replication.
What is the severity of CVE-2022-26501?
CVE-2022-26501 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2022-26501?
CVE-2022-26501 affects Veeam Backup & Replication versions between 10.0.0.4442 and 10.0.1.4854, and versions between 11.0.0.825 and 11.0.1.1261.
How can an attacker exploit CVE-2022-26501?
An attacker can exploit CVE-2022-26501 by accessing internal API functions of Veeam Distribution Service in the Backup & Replication application.
Is authentication required to exploit CVE-2022-26501?
No, CVE-2022-26501 allows unauthenticated users to access the internal API functions.