| KB ID: | 4934 |
| Product: | Veeam Backup & Replication | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2 |
| Published: | 2026-10-06 |
| Last Modified: | 2026-10-06 |
All vulnerabilities listed in this article:
Customers are reminded that Veeam Backup & Replication version 12 will reach End of Support on 2027-02-28.
A vulnerability allowing a low-privileged user with the Backup Viewer role to perform remote code execution (RCE) on the Veeam Backup Server through insecure deserialization of untrusted data received via the Mount Service.
Severity: Critical
CVSS v4.0 Score: 9.4CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: Reported through HackerOne.
This vulnerability was fixed starting in the following build:
A vulnerability allowing an authenticated user with the Backup Viewer role to modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials on the Veeam Backup Server.
Severity: Medium
CVSS v4.0 Score: 6.1CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Source: Reported through HackerOne.
This vulnerability was fixed starting in the following build:
A reflected cross-site scripting vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of an authenticated portal user who opens a crafted link.
Severity: Medium
CVSS v4.0 Score: 4.8CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Source: Reported through HackerOne.
This vulnerability was fixed starting in the following build:
If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case.
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case