Loading...
Loading...
CVE-2026-58070 A vulnerability that causes guest OS credentials used for Application Aware processing to be recorded in cleartext in logs on the guest machine. Severity: MediumCVSS v4.0 Score: 6.8CVSS: AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NAffected Deployment Type: Windows-based Veeam Backup & Replication | Veeam Software ApplianceSource: Reported through HackerOne. Affected Product Veeam Backup & Replication 13.0.2.29 and all earlier version 13 builds.Note: Older versions (e.g., 12.x) are not affected. Solution This vulnerability was fixed starting in the following builds: Veeam Backup & Replication 13.1 (build 13.1.0.411) Veeam Backup & Replication 13.0.3 (build 13.0.3.63)
Click on a version to see all relevant bugs
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.