Skip to main content
Vulnerability Database/CVE-2026-58069

CVE-2026-58069: Veeam Backup Path Traversal Vulnerability

CVE-2026-58069 is a path traversal vulnerability in Veeam Backup & Replication that allows authenticated Cloud Connect tenants to read arbitrary files on service provider hosts. This article covers technical details, affected versions, security impact, and mitigation steps.

Published:

CVE-2026-58069 Overview

CVE-2026-58069 is a path traversal vulnerability [CWE-22] in Veeam Backup & Replication. The flaw allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host. Exploitation requires valid tenant credentials but no user interaction. The vulnerability affects the confidentiality of the service provider environment and crosses a security boundary from tenant to provider. Veeam has published a Knowledge Base advisory documenting the issue and remediation guidance.

Critical Impact

An authenticated Cloud Connect tenant can read arbitrary files on the service provider host, exposing credentials, configuration data, and other tenants' metadata stored on the shared infrastructure.

Affected Products

  • Veeam Backup & Replication (Cloud Connect component)
  • Veeam service provider deployments hosting multi-tenant Cloud Connect environments
  • Refer to the Veeam Knowledge Base Article for the full list of affected builds

Discovery Timeline

  • 2026-10-07 - CVE CVE-2026-58069 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-58069

Vulnerability Analysis

The vulnerability is a path traversal weakness in the Veeam Backup & Replication Cloud Connect service. Cloud Connect enables service providers to offer backup-as-a-service to tenants over a network channel. When an authenticated tenant interacts with the provider endpoint, insufficient validation of file path inputs permits the tenant to escape the intended tenant-scoped directory. The attacker can then reference files outside the sandbox using relative path sequences. The result is unauthorized read access to arbitrary files residing on the service provider host operating system.

The attack is executed over the network and requires only low-privileged tenant credentials. There is no user interaction requirement, and the scope changes because the compromised data belongs to the provider rather than the tenant. Read access to provider-side files can expose credentials, Veeam configuration, SSL private keys, and data for other tenants hosted on the same system.

Root Cause

The root cause is improper limitation of a pathname to a restricted directory [CWE-22]. The affected code path accepts a tenant-supplied file reference and resolves it against the host filesystem without canonicalizing the path or enforcing a strict allowlist of permitted directories. Sequences such as ../ are not neutralized, enabling traversal outside the tenant boundary.

Attack Vector

An attacker with valid Cloud Connect tenant credentials authenticates to the service provider endpoint over the network. The attacker then issues a request containing a crafted file path that traverses outside the tenant-scoped directory. The service returns the file contents to the authenticated session. No elevation of privileges on the host operating system is required, and no interaction from provider personnel is needed.

Technical specifics of the vulnerable method and request format have not been publicly disclosed. See the Veeam Knowledge Base Article for vendor-provided technical details.

Detection Methods for CVE-2026-58069

Indicators of Compromise

  • Cloud Connect tenant sessions containing path traversal sequences such as ..\ or ../ in file reference parameters
  • Unexpected read access to files outside the tenant directory on the Veeam service provider host, including configuration files, certificate stores, and other tenants' repositories
  • Anomalous volume of file-read operations originating from a single authenticated tenant account
  • Access to sensitive host paths such as C:\ProgramData\Veeam\, C:\Windows\System32\config\, or SSH key directories by the Veeam Cloud Connect service account

Detection Strategies

  • Enable detailed audit logging on the Veeam Backup & Replication server and inspect Cloud Connect tenant request logs for traversal patterns
  • Correlate Veeam service process file-access events with the originating authenticated tenant identifier to identify out-of-scope reads
  • Deploy file integrity and access monitoring on the service provider host to flag reads of sensitive directories by the Veeam service account

Monitoring Recommendations

  • Forward Veeam Cloud Connect, Windows Security, and Sysmon events to a centralized SIEM for correlation across tenant sessions
  • Baseline normal tenant request patterns and alert on deviations in request size, path depth, or encoded traversal characters
  • Review authentication logs for Cloud Connect tenants exhibiting unusual connection frequency or source IP changes

How to Mitigate CVE-2026-58069

Immediate Actions Required

  • Apply the patched Veeam Backup & Replication build identified in the Veeam Knowledge Base Article to all service provider installations
  • Audit active Cloud Connect tenant accounts and disable or rotate credentials for any tenant exhibiting suspicious activity
  • Review service provider host filesystems for recent unauthorized access to sensitive files and rotate exposed secrets

Patch Information

Veeam has released fixed builds that address the path traversal flaw in the Cloud Connect component. Service providers should consult the Veeam Knowledge Base Article for the exact fixed version numbers and upgrade procedures that apply to their deployment.

Workarounds

  • Restrict network reachability of the Cloud Connect endpoint to known tenant source networks until patching is complete
  • Enforce strong tenant authentication and rotate tenant credentials to reduce the risk of unauthorized Cloud Connect sessions
  • Run the Veeam Cloud Connect service under a least-privilege account that cannot read sensitive host directories outside the Veeam data paths
  • Isolate the Veeam Backup & Replication host from other sensitive workloads to reduce the blast radius of a successful file read
bash
# Configuration example
# Review Veeam Cloud Connect tenant audit logs on the service provider host
Get-WinEvent -LogName 'Veeam Backup' | \
  Where-Object { $_.Message -match '\.\./|\.\.\\' } | \
  Format-List TimeCreated, Id, Message

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.