CVE-2026-58074
Veeam · ONE
Veeam ONE is vulnerable to a code injection flaw that allows a high-privileged user to execute arbitrary code on the server.
Executive summary
A critical code injection vulnerability in Veeam ONE versions up to 13.0.2 allows authenticated attackers with high privileges to execute arbitrary code on the server.
Vulnerability
This is a code injection vulnerability (CWE-94) that requires an attacker to possess high-level administrative privileges to successfully execute arbitrary code.
Business impact
The ability for a high-privileged user to execute arbitrary code constitutes a total compromise of the affected server. With a CVSS score of 8.6, the business impact is severe, potentially leading to unauthorized data access, system manipulation, or the deployment of further malicious payloads within the management environment.
Remediation
Immediate Action: Update Veeam ONE to the latest secure version as specified in the vendor advisory (KB4892) to eliminate the injection vector.
Proactive Monitoring: Audit administrative access logs for unusual command execution patterns or unauthorized changes to system configurations.
Compensating Controls: Enforce strict access control policies and the principle of least privilege to ensure that only authorized personnel can interact with the server management interfaces.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Security teams must treat this vulnerability as high priority. Immediately review the official Veeam KB4892 advisory and apply the recommended updates to ensure that the code injection flaw is remediated and the management server is secured against potential internal threats.