Critical Veeam Backup & Replication Flaw Exposes Guest OS Credentials
Key Takeaways A critical vulnerability (CVE-2026-65641) in Veeam ONE 13 allows remote, unauthenticated attackers to force SMB authentication from the service account. This flaw could expose Net-NTLM...
Key Takeaways
- A critical vulnerability (CVE-2026-65641) in Veeam ONE 13 allows remote, unauthenticated attackers to force SMB authentication from the service account.
- This flaw could expose Net-NTLM credentials, enabling attackers to crack passwords, relay authentication, or escalate privileges.
- Veeam ONE 13.1.0.7034 and all prior Veeam ONE 13 builds are affected, but legacy 12.x releases are not.
- Patches are available, and immediate upgrades to Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) or Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159) are advised.
Veeam ONE Flaw Exposes Critical Credentials
Veeam has issued a critical security advisory concerning a significant vulnerability within its Veeam ONE 13 monitoring solution. This flaw, identified as CVE-2026-65641, could allow an attacker operating remotely and without prior authentication to compel the product’s service account into an SMB authentication attempt.
Table Of Content
The severity of this issue is underscored by its CVSS v4.0 score of 9.3. The vulnerability was brought to Veeam’s attention via the HackerOne bug bounty program.
Affected Versions and Impact
The vulnerability specifically impacts Veeam ONE 13.1.0.7034 and all earlier builds within the Veeam ONE 13 series. Importantly, Veeam has confirmed that previous 12.x versions of the software are not susceptible to this particular flaw.
CVE-2026-65641 arises from a condition where an unauthenticated remote adversary can trigger an SMB authentication attempt originating from the Veeam ONE service account. In Windows environments, such authentication coercion vulnerabilities are particularly dangerous. They can lead to the exposure of Net-NTLM authentication material to a server controlled by the attacker.
Once captured, this authentication data can be exploited in several ways: an attacker might attempt offline password cracking, relay the captured credentials to another service to gain unauthorized access, or leverage the service account’s permissions to penetrate deeper into the network infrastructure.
The extent of potential damage hinges on the configuration of the Veeam ONE service account. Factors such as whether it possesses elevated privileges, access to backup infrastructure components, or broad permissions within Active Directory environments will dictate the severity of a compromise. This vulnerability is especially critical for organizations that rely on Veeam ONE for monitoring their backup and virtual environments, which frequently house highly privileged accounts, sensitive storage credentials, hypervisor access, and disaster recovery systems.
Full details regarding this vulnerability are available in the Veeam Knowledge Base article 4905, published on August 25, 2026. A successful compromise of a monitoring service account could provide attackers with a direct route to critical backup administration systems.
Available Fixes and Mitigation
Veeam has promptly released patches to address this vulnerability. Organizations currently operating Veeam ONE 13.1 should upgrade to Veeam ONE 13.1 Patch 0, build 13.1.0.7233. For those running Veeam ONE 13.0.2, the recommended action is to install Patch 1, build 13.0.2.7159. The company has confirmed that these updated builds contain the necessary fixes.
What You Should Do
- Apply Patches Immediately: Identify all Veeam ONE 13 deployments and verify their current build numbers. Any environment running a version older than 13.1.0.7233 or 13.0.2.7159 should be considered vulnerable until the appropriate update is applied.
- Review Outbound SMB Activity: Security teams should scrutinize outbound SMB and NTLM authentication traffic originating from Veeam ONE servers. Unexpected SMB connections to untrusted hosts, particularly over TCP port 445, could signal an attempt at authentication coercion.
- Implement Network Controls: Restrict outbound SMB traffic from Veeam ONE servers using network firewalls and other controls to minimize exposure.
- Enable SMB Security Features: Utilize SMB signing and Extended Protection for Authentication to help mitigate the risks associated with credential relay attacks.
- Adhere to Least Privilege: Ensure that the Veeam ONE service account operates with the principle of least privilege. It should not possess unnecessary permissions such as domain administrator, local administrator, backup repository access, or virtualization management privileges.
- Monitor for Suspicious Activity: Regularly monitor logs for authentication failures, unusual activity from the service account, and any suspicious access attempts to backup systems. This can help detect potential abuse of compromised credentials.
This disclosure underscores the persistent threat posed by authentication coercion vulnerabilities within critical enterprise management platforms. Prompt application of Veeam’s patches and proactive measures to reduce unnecessary NTLM exposure are crucial steps in safeguarding backup infrastructure against credential theft and lateral movement.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.