CVE-2024-40718: Veeam Backup For Nutanix Ahv

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.

Affected products

  • Veeam Backup For Nutanix Ahv: from 12, up to and including 12.5.1.8
  • Veeam Backup For Oracle Linux Virtualization Manager And Red Hat Virtualization: from 12, up to and including 12.4.1.45
  • Veeam Nutanix Ahv: before 12.6.0 (fixed in 12.6.0)
  • Veeam Nutanix Kvm: before 12.5.0 (fixed in 12.5.0)

Published 2024-09-07. Last modified 2026-06-17.