CVE-2026-58075

Veeam · ONE

Veeam ONE contains an arbitrary file read vulnerability that allows unauthenticated attackers to access sensitive host files and escalate privileges locally.

Executive summary

An unauthenticated arbitrary file read vulnerability in Veeam ONE poses a critical risk of full system compromise and unauthorized data access.

Vulnerability

This vulnerability involves improper authentication, allowing an unauthenticated remote attacker to read arbitrary files from the underlying host. Successful exploitation can be leveraged to escalate local privileges.

Business impact

The ability for an unauthenticated user to read sensitive files on a management server like Veeam ONE represents a severe security breach. Given the CVSS score of 8.7, this flaw could lead to the exposure of configuration files, credentials, or system data, facilitating further lateral movement and total system compromise.

Remediation

Immediate Action: Update Veeam ONE to the latest version as specified in the vendor advisory (KB4892).

Proactive Monitoring: Review system access logs for unusual file read requests or unexpected administrative activity originating from unauthorized sources.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting sensitive file paths on the application server.

Exploitation status

Public Exploit Available: false

Analyst recommendation

The severity of this vulnerability necessitates immediate attention. Organizations should prioritize patching their Veeam ONE instances to the latest secure version to prevent unauthorized access and potential privilege escalation.