Veeam Updater Vulnerability Allows Privilege Escalation

Veeam Updater Vulnerability Allows Privilege Escalation

First seen 22 Jul 2026, 12:54 UTC Heise.Dewww.veeam.com 82% similarity 70.5

Article Content

Browse articles
ThreatCluster

A vulnerability in the Veeam Updater component (CVE-2026-56844) allows local users to escalate privileges and gain root access to the operating system. This high-risk flaw affects the Veeam Backup & Replication server on Linux-based systems, while Windows-based servers are not directly impacted. An update (version 12.3.0.65) was released on July 15, 2026, to address this issue. Users with automatic updates enabled will receive the patch automatically, while others need to install it manually. The vulnerability was reported through HackerOne, highlighting the importance of timely updates for system security. Administrators are advised to check their systems to ensure they are running the latest version of the updater component.

Key Points: • CVE-2026-56844 allows local privilege escalation in Veeam Backup & Replication. • The vulnerability affects Linux-based systems; Windows servers are not impacted. • An update to fix the issue was released on July 15, 2026.

ThreatCluster AI

Timeline

2026-07-15
Veeam releases patch for updater vulnerability
Version 12.3.0.65 of the Veeam updater component was released to address the privilege escalation flaw.
Heise.De
2026-07-22
CVE-2026-56844 published
The vulnerability in the Veeam Updater component was officially published, allowing local privilege escalation.
Heise.De

Community

Browse all →