CVE-2026-64632
8.5Veeam · ONE
A vulnerability in Veeam ONE allows a low-privileged user to capture NTLM credentials from the Reporter service account, potentially leading to unauthorized system access.
Executive summary
A high-severity credential exposure vulnerability in Veeam ONE allows low-privileged users to intercept NTLM service account credentials, posing a significant risk of lateral movement.
Vulnerability
The flaw is classified as CWE-522, involving insufficiently protected credentials. An authenticated low-privileged user can leverage this weakness to capture the NTLM hash of the Reporter service account, which may grant elevated privileges within the environment.
Business impact
Successful exploitation of this vulnerability presents a severe risk to organizational security, as the compromised service account credentials could be used to escalate privileges or perform unauthorized lateral movement. Given the CVSS score of 8.5, this high-severity issue necessitates immediate attention to prevent the compromise of sensitive administrative accounts and internal infrastructure.
Remediation
Immediate Action: Review the official Veeam knowledge base article KB4892 and apply the latest security updates provided by the vendor to remediate the credential exposure.
Proactive Monitoring: Audit access logs for unusual authentication patterns or unauthorized requests directed at the Reporter service component.
Compensating Controls: Implement network segmentation and restrict access to the Veeam ONE interface to known, trusted users to minimize the potential for exploitation by low-privileged entities.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Veeam ONE versions 13.0.2 and earlier should prioritize patching to mitigate the risk of credential theft. Because this vulnerability facilitates the compromise of service account credentials, prompt remediation is essential to maintain the integrity of the backup management environment and prevent broader network compromise.