CVE-2026-58075
Veeam · ONE
Veeam ONE contains an arbitrary file read vulnerability that allows unauthenticated attackers to access sensitive host files and escalate privileges locally.
Executive summary
An unauthenticated arbitrary file read vulnerability in Veeam ONE poses a critical risk of full system compromise and unauthorized data access.
Vulnerability
This vulnerability involves improper authentication, allowing an unauthenticated remote attacker to read arbitrary files from the underlying host. Successful exploitation can be leveraged to escalate local privileges.
Business impact
The ability for an unauthenticated user to read sensitive files on a management server like Veeam ONE represents a severe security breach. Given the CVSS score of 8.7, this flaw could lead to the exposure of configuration files, credentials, or system data, facilitating further lateral movement and total system compromise.
Remediation
Immediate Action: Update Veeam ONE to the latest version as specified in the vendor advisory (KB4892).
Proactive Monitoring: Review system access logs for unusual file read requests or unexpected administrative activity originating from unauthorized sources.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting sensitive file paths on the application server.
Exploitation status
Public Exploit Available: false
Analyst recommendation
The severity of this vulnerability necessitates immediate attention. Organizations should prioritize patching their Veeam ONE instances to the latest secure version to prevent unauthorized access and potential privilege escalation.