CVE-2024-39718: Veeam Backup & Replication

High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.

An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.

Affected products

  • Veeam Veeam Backup & Replication: from 12.0.0.1402, before 12.2.0.334 (fixed in 12.2.0.334)

Published 2024-09-07. Last modified 2026-06-17.