CVE-2025-64392: XSS
Published Oct 7, 2026
·Updated
This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link.
Affected Software
1 affected component
Veeam Backup Enterprise Manager
Event History
Oct 7, 2026
CVE Published
via MITRE·08:49 AM
Data Sourced
via MITRE·08:49 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs to craft a link and convince a Veeam Backup Enterprise Manager portal user to open it. The CVSS vector indicates low privileges are required and user interaction is required.
2
Who is exposed to the impact?
Portal users who open an attacker-crafted link are exposed to script execution in their browser. The stated impact is on subsequent systems, with low confidentiality and integrity effects and no availability effect.