Remote Code Execution Vulnerability in Veeam Backup & Replication Software
CVE-2025-55125

7.8HIGH

Key Information:

Vendor

Veeam

Vendor
CVE Published:
8 January 2026

What is CVE-2025-55125?

A vulnerability in Veeam Backup & Replication software permits a Backup or Tape Operator to execute remote code as a root user by creating a specially crafted backup configuration file. This security flaw can be exploited to gain unauthorized access and control over affected systems, potentially leading to significant data breaches and operational disruptions.

Affected Version(s)

Backup And Recovery 13.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55125 : Remote Code Execution Vulnerability in Veeam Backup & Replication Software