Veeam has disclosed a critical security vulnerability in Veeam ONE 13 that could allow an unauthenticated remote attacker to coerce SMB authentication from the product’s service account.
Tracked as CVE-2026-65641, the issue carries a CVSS v4.0 score of 9.3 and was reported through the HackerOne vulnerability disclosure program.
It affects Veeam ONE 13.1.0.7034 and all earlier Veeam ONE 13 builds. Veeam said legacy 12.x releases are not affected by this vulnerability.
CVE-2026-65641 stems from a condition in which a remote unauthenticated attacker can trigger SMB authentication attempts from the Veeam ONE service account.
Such flaws in Windows environments are significant because they can expose Net-NTLM authentication material to an attacker-controlled server.
An attacker could capture the authentication exchange, attempt offline password cracking, relay the captured credentials to another service, or use the service account’s permissions to advance further into a network.
Veeam Backup & Replication Flaw Exposes
The impact depends heavily on how the Veeam ONE service account is configured, including whether it has elevated privileges, access to backup infrastructure, or permissions across Active Directory environments.
The issue is especially concerning for organizations that use Veeam ONE to monitor backup and virtual infrastructure. Backup environments often contain highly privileged accounts, storage credentials, hypervisor access, and systems used for disaster recovery.
The flaw is documented in Veeam Knowledge Base article 4905, published on August 25, 2026. Compromise of a monitoring service account could provide attackers with a valuable path to backup administration systems.
Veeam has released fixes for affected versions. Organizations running Veeam ONE 13.1 should upgrade to Veeam ONE 13.1 Patch 0, build 13.1.0.7233.
Those using Veeam ONE 13.0.2 should install Patch 1, build 13.0.2.7159. The company stated that the vulnerability is fixed in these updated builds.
Administrators should identify all Veeam ONE 13 deployments and verify their installed build numbers. Environments using versions earlier than 13.1.0.7233 or 13.0.2.7159 should be treated as exposed until the relevant update is applied.
Security teams should also review outbound SMB and NTLM authentication activity from Veeam ONE servers. Unexpected SMB connections to untrusted hosts, particularly over TCP port 445, may indicate an attempt to coerce authentication.
Network controls that restrict outbound SMB traffic can reduce exposure. At the same time, SMB signing and Extended Protection for Authentication can help limit credential relay risks.
Organizations should ensure that the Veeam ONE service account adheres to least-privilege principles and does not hold unnecessary permissions such as domain, local administrator, backup repository, or virtualization management permissions.
Monitoring logs for authentication failures, unusual service-account activity, and suspicious access to backup systems can help identify potential abuse.
The disclosure highlights the continued risk posed by authentication coercion vulnerabilities in enterprise management platforms.
Applying Veeam’s patches promptly and reducing unnecessary NTLM exposure are key steps for defending backup infrastructure from credential theft and lateral movement.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

