CVE-2024-22022: Veeam Recovery Orchestrator

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service.

Affected products

  • Veeam Recovery Orchestrator: before 7.0 (fixed in 7.0)

Published 2024-02-07. Last modified 2026-06-17.