CVE-2026-58075

Published Aug 4, 2026

Last updated 14 days ago

CVSS high 8.7
Veeam ONE

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-58075 is a vulnerability found in Veeam ONE that allows an unauthenticated attacker to read arbitrary files from the host system. This unauthorized access to files can potentially expose sensitive data such as configuration files, credentials, or logs. Furthermore, the ability to read arbitrary files can be leveraged by an attacker to escalate privileges locally on the affected system. This flaw is classified as an improper authentication weakness (CWE-287).

Description
A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
Source
support@hackerone.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

support@hackerone.com
CWE-287

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.