CVE-2024-40713: Veeam Backup & Replication

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.

Affected products

  • Veeam Veeam Backup & Replication: before 12.2.0.334 (fixed in 12.2.0.334)

Published 2024-09-07. Last modified 2026-06-17.