AI description
CVE-2026-58075 is a vulnerability found in Veeam ONE that allows an unauthenticated attacker to read arbitrary files from the host system. This unauthorized access to files can potentially expose sensitive data such as configuration files, credentials, or logs. Furthermore, the ability to read arbitrary files can be leveraged by an attacker to escalate privileges locally on the affected system. This flaw is classified as an improper authentication weakness (CWE-287).
- Description
- A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
- Source
- support@hackerone.com
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- support@hackerone.com
- CWE-287
- Hype score
- Not currently trending
⚠️⚠️ CVE-2026-64633 (CVSS 10.0) + CVE-2026-58075 (CVSS 8.7): Unauthenticated RCE and arbitrary file read on Veeam ONE agent host 🔗FOFA Link: https://t.co/AMypDZDjwq 🎯1.1K+ Results are found on https://t.co/NBEEGu7ePJ in the past year. FOFA Query: title="Veeam ONE"
@fofabot
6 Aug 2026
6522 Impressions
19 Retweets
51 Likes
26 Bookmarks
0 Replies
0 Quotes
Veeam ONE 13.1 patches six vulnerabilities, including CVE-2026-64633 allowing unauthenticated remote code execution on the agent host (CVSS 10.0 Critical). CVE-2026-58075 permits arbitrary file reads leading to local privilege escalation (CVSS 8.7). Both issues affect the backup
@WorldCyberNewsX
5 Aug 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes