logo

Exploit for Veeam Recovery Orchestrator auth bypass available, patch now

ID: 8577c3c7-eddb-5adc-b237-62e64fcefdfd

STIX ID: report--8577c3c7-eddb-5adc-b237-62e64fcefdfd

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-06-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical authentication bypass (CVE-2024-29855, CVSS 9.0) affects Veeam Recovery Orchestrator versions 7.0.0.337 and 7.1.0.205 and earlier due to a hardcoded JWT secret, allowing unauthenticated administrative access; a public PoC exploit demonstrating username/role enumeration and token-timestamp techniques has been published and vendors have released patched versions (7.1.0.230 and 7.0.0.379) that should be applied promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.