CVE-2026-64633

Published Aug 4, 2026

Last updated 15 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-64633 is a vulnerability identified in Veeam ONE that permits remote unauthenticated code execution on the agent host. This flaw allows an attacker to run arbitrary code on the affected system without needing authentication or user interaction. The vulnerability impacts Veeam ONE version 13.0.2.6723 and all prior builds of version 13. Veeam has released an update, version 13.1.0.7034, to address this and other related issues. The vulnerability was reported through HackerOne.

Description
A vulnerability allowing remote unauthenticated code execution on the agent host.
Source
support@hackerone.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

support@hackerone.com
CWE-94

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.