Cleartext Credential Exposure Vulnerability in Veeam Backup and Replication
CVE-2026-58070

6.8MEDIUM

Key Information:

Vendor

Veeam

Vendor
CVE Published:
26 August 2026

What is CVE-2026-58070?

This vulnerability allows sensitive guest OS processing credentials to be recorded in cleartext within a support log on the guest operating system. As a result, any user with read access to this log file can potentially recover privileged account credentials, leading to unauthorized access and privilege escalation. Security measures should be implemented to secure log files and minimize the risk of exposure.

Affected Version(s)

Backup and Replication 0 < 13.0.3

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.