Vulnerability
Published 2026-08-25
Verified 2026-09-19

Veeam ONE SMB authentication coercion (CVE-2026-65641)

Veeam KB4905 (published 25 August 2026) documents CVE-2026-65641: an unauthenticated network attacker can coerce SMB authentication from the Veeam ONE service account. Vendor severity Critical, CVSS 4.0 score 9.3 (vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L), reported via HackerOne. Affected: Veeam ONE 13.1.0.7034 and all earlier version 13 builds. Veeam states older 12.x builds are not affected. Fixed in Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159). WA SOC shared advisory 20260828001 pointed operators at this class of issue. Patch promptly; Veeam notes attackers often reverse-engineer disclosed patches.

Product
Veeam ONE
Versions
13.1.0.7034 and earlier v13 builds (12.x not affected per vendor)
CVSS
(CVSS 4.0, vendor)
Exploited in Australia?
unknown
Patch to
13.1.0.7233 or 13.0.2.7159

Primary: Veeam KB4905 · Vendor: WA SOC shared advisories (index) · CVE: CVE-2026-65641 · NVD

vulnerabilities australia network cloud