# Veeam Backup & Replication privilege escalation flaw

Published: 2026-07-15 · Severity: medium
Canonical: https://vorant.io/reports/437bb01c-eb54-5bf5-8e6c-4cc448489f98/veeam-backup-replication-privilege-escalation-flaw

> A vulnerability in Veeam Backup & Replication versions before 12.3.0.65 allows an attacker to escalate privileges.

ANSSI-CERT-FR has issued an advisory regarding a privilege escalation vulnerability affecting Veeam Backup & Replication versions prior to 12.3.0.65. Exploitation of this flaw could allow an attacker to elevate their privileges on affected systems, potentially leading to further compromise of backup infrastructure.

Veeam has published a security bulletin (kb4879) detailing the issue and providing patches. Organizations using affected versions of Veeam Backup & Replication are advised to consult the vendor's bulletin and apply the recommended fixes promptly, given the critical role backup systems play in ransomware resilience and disaster recovery.

## Mentioned in this report

- Vulnerabilities: CVE-2026-0000

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0878

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/437bb01c-eb54-5bf5-8e6c-4cc448489f98/veeam-backup-replication-privilege-escalation-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
