CVE-2026-65641

Published Aug 26, 2026

Last updated 25 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-65641 is a vulnerability found in Veeam ONE that allows an unauthenticated network attacker to coerce Server Message Block (SMB) authentication from the service account. This flaw enables an attacker to force the server to authenticate to a system they control, potentially leading to relay attacks against other hosts. The vulnerability affects Veeam ONE version 13.1.0.7034 and all earlier version 13 builds. Veeam has released updates, specifically Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159), to address this issue.

Description
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
Source
support@hackerone.com
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

support@hackerone.com
CWE-288

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.