CVE-2023-27532: Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2023-08-22. EPSS: 81.3% chance of exploitation in the next 30 days.
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
Affected products
- Veeam Veeam Backup & Replication: before 11.0.1.1261 (fixed in 11.0.1.1261); version 11.0.1.1261 only; version 12.0.0.1420 only
Published 2023-03-10. Last modified 2026-06-17.