CVE-2026-58069: Path Traversal
Published Oct 7, 2026
·Updated
This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host.
Affected Software
1 affected component
Veeam Backup & Replication
Event History
Oct 7, 2026
CVE Published
via MITRE·08:48 AM
Data Sourced
via MITRE·08:48 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An authenticated Cloud Connect tenant can exploit it. The issue affects the service provider host rather than being limited to the tenant's own environment.
2
What access does an attacker need?
The attacker needs valid authentication as a Cloud Connect tenant. No user interaction is required, and the attack can be performed over the network.
3
What is the likely impact if exploitation succeeds?
A successful attacker can read arbitrary files on the service provider host. This can expose sensitive data stored or accessible on that host.