External risk intelligence

Veeam Backup & Replication Remote Code Execution via Malicious Password

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-59468

The vulnerability affects Veeam Backup & Replication, which is typically deployed in internal, restricted network segments to manage data protection. While the attack vector is network-based, it requires an authenticated Backup Administrator role, making direct exposure to the public internet uncommon and inconsistent with standard deployment practices for backup infrastructure.

Remote Code Execution

Veeam Backup \& Replication

13.0.0.4967 to before 13.0.1.1071

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Veeam Backup & Replication software that could allow a malicious actor with administrator privileges to execute arbitrary code on the system. This type of security flaw, if exploited, could potentially compromise the integrity and confidentiality of backup data.

  • Administrator credentials can lead to system compromise.
  • Backup system compromise risks data integrity and access.
  • Confirm relevance and assess exposure for critical systems.

Attack Path

How an attacker could exploit the issue

An attacker with Backup Administrator privileges can trigger this vulnerability by sending a specially crafted password. This allows them to execute arbitrary code on the server with the privileges of the postgres user, potentially leading to a complete compromise of the backup system.

  • Requires authenticated administrator access.
  • Sending a malicious password parameter.
  • Remote code execution with elevated privileges.

Live Threat

Current exploitation, exposure, and threat context

A Backup Administrator with administrative privileges could potentially execute arbitrary code on the affected system by exploiting a weakness in how password parameters are handled. This could impact the integrity and availability of the backup service and the data it manages.

  • Backup service code execution.
  • Malicious password parameter sent.
  • System compromise and data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability affects Veeam Backup & Replication, allowing remote code execution by a privileged Backup Administrator. Ownership likely falls to the backup administrators or the infrastructure team managing the backup environment. The first practical step is to identify all instances of the affected Veeam software, confirm their exposure, and determine the accountable owner before planning remediation.

  • Backup or infrastructure team ownership.
  • Verify affected Veeam instances.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Veeam Backup & Replication?

Veeam Backup & Replication is a data protection and disaster recovery software suite. Organizations use it to back up, restore, and replicate virtual, physical, and cloud-based workloads. It acts as a central management platform for enterprise data, often interacting with underlying database components like PostgreSQL to maintain configuration settings and backup metadata.

What does CVE-2025-59468 mean?

This CVE refers to a security flaw classified as CWE-77, known as Command Injection. Essentially, the software fails to properly sanitize input when handling password parameters. Because the application does not filter these inputs correctly, a user with specific privileges can inject and execute unauthorized system-level commands, allowing the server to perform actions dictated by the malicious input.

How is this vulnerability triggered?

The trigger requires an actor to hold valid Backup Administrator credentials to interact with the system's authentication process. By submitting a specially crafted password parameter during an administrative session, the attacker forces the underlying system to process unintended commands. Simply having network access is insufficient; the attack will not trigger without successful authentication as a Backup Administrator.

Should I be worried about this vulnerability?

While the vulnerability has a network-based attack vector, Halo Surface Signal notes that Veeam Backup & Replication is typically deployed within internal, restricted network segments. Because this issue requires an authenticated administrator role, the risk is lower for systems not directly reachable from the public internet. You should assess whether your instance is reachable from untrusted zones or if internal access controls are currently the only barrier.

How do I start addressing this issue?

Begin by auditing your infrastructure to locate all active installations of the affected Veeam software versions. Once identified, coordinate with the team responsible for backup operations to confirm current deployment configurations. Your primary goal is to ensure the backup environment remains secure while you coordinate with the vendor to verify the availability of an update that remediates the input handling weakness.

References