Loading
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
Use CWE-22, Veeam vendor hub and Veeam Backup \& Replication product page to widen CVE-2022-26500 into its surrounding weakness, vendor, and product context.
Additional editorial context is available in The Weekly Cybersecurity Brief: March 15th, 2026.