CVE-2024-40709: Veeam Agent

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.

Affected products

  • Veeam Agent: from 6, up to and including 6.1.2.1781
  • Veeam Backup And Recovery: from 12.1.2, up to and including 12.1.2

Published 2024-09-07. Last modified 2026-06-17.