CVE-2022-26501

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
17/03/2022
Last modified:
04/04/2025

Description

Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:* 10.0.0.4442 (including) 10.0.1.4854 (excluding)
cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:* 11.0.0.825 (including) 11.0.1.1261 (excluding)
cpe:2.3:a:veeam:veeam_backup_\&_replication:10.0.1.4854:-:*:*:*:*:*:*
cpe:2.3:a:veeam:veeam_backup_\&_replication:10.0.1.4854:p20201202:*:*:*:*:*:*
cpe:2.3:a:veeam:veeam_backup_\&_replication:10.0.1.4854:p20210609:*:*:*:*:*:*
cpe:2.3:a:veeam:veeam_backup_\&_replication:11.0.1.1261:-:*:*:*:*:*:*
cpe:2.3:a:veeam:veeam_backup_\&_replication:11.0.1.1261:p20211123:*:*:*:*:*:*
cpe:2.3:a:veeam:veeam_backup_\&_replication:11.0.1.1261:p20211211:*:*:*:*:*:*