← Back to browse · API

CVE-2022-26500

Severity
HIGH
CVSS
8.8
EPSS
0.05828
Risk score
62.24
CISA KEV
Yes
PoC
No
Published
2022-03-17
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-31058, GHSA-2VW2-587W-G9V6
Products
Veeam:Backup & Replication, n/a:n/a n/a
Sources
cisa.gov CVE-2022-26500
euvd EUVD-2022-31058

Description

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

References