Veeam Backup & Replication Remote Code Execution Vulnerability for Backup Administrators in High Availability Deployments

Vulnerability

A remote code execution vulnerability has been identified in Veeam Backup & Replication version 13.0.1.1071 and earlier, specifically within high availability deployments. This vulnerability allows an authenticated user with the Backup Administrator role to execute arbitrary code remotely.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected Veeam Backup & Replication server.

Remediation

This vulnerability has been fixed in Veeam Backup & Replication version 13.0.1.2067.

Added: Mar 12, 2026, 3:20 PM
Updated: Mar 12, 2026, 3:20 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
4.0
remediation
7.7
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.