CVE-2024-29855: Veeam Recovery Orchestrator
Critical severity, CVSS 9.0. EPSS: 21.6% chance of exploitation in the next 30 days.
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
Affected products
- Veeam Recovery Orchestrator: before 7.0.0.379 (fixed in 7.0.0.379); from 7.1, before 7.1.0.230 (fixed in 7.1.0.230)
Published 2024-06-11. Last modified 2026-06-17.