CVE-2024-22022: Veeam Recovery Orchestrator
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service.
Affected products
- Veeam Recovery Orchestrator: before 7.0 (fixed in 7.0)
Published 2024-02-07. Last modified 2026-06-17.