Skip to content

CVE-2026-58070: Cleartext Guest OS Credentials Disclosure in Veeam Backup Support Logs

HERMES

HERMES THREAT SCORE & CREDENTIAL EXPOSURE RISK

Target: Veeam Backup & Replication Diagnostic Logging Subsystem
Confidence: 97%
78 / 100
HIGH

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 17 / 20
Threat Activity 15 / 20
Weaponization 16 / 20
Exposure 15 / 20
Prevalence 19 / 20
Impact 18 / 20
Exploit Maturity 16 / 20
Attack Chain Potential 19 / 20
βš–οΈ Divergence & Operational Rationale

Hermes elevates CVE-2026-58070 to 78 (HIGH). Although vendor scoring classifies this as Medium severity due to the requirement for local filesystem read access, the operational blast radius is critical: it exposes plaintext passwords for domain controllers and mission-critical database instances protected by VSS Application-Aware processing. Any low-privileged local user or lateral attacker can harvest tier-0 administrative credentials without elevation.

πŸ•ΈοΈ Connected Knowledge Graph & Provenance

CVE-2026-58070: Cleartext Guest OS Credentials Disclosure in Veeam Backup Support LogsVULNERABILITY

Connected Nodes: 1
Active Relationships (Outgoing)
→ affectsPRODUCTVeeam Backup & Replication
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

πŸ” Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier.”

Supporting Verified Evidence:

MetricTechnical SpecificationOperational Impact
CVE IdentifierCVE-2026-58070Official NVD / MITRE tracking record
Vendor / SoftwareVeeam Software / Backup & ReplicationInfrastructure backup and recovery
Affected ReleasesVBR 12.x and 13.x prior to August 2026 hotfixDeployments with Guest Processing enabled
Vulnerability ClassCWE-532: Information Exposure Through Log FilesEnterprise credential leakage
Required AccessLocal read access to Veeam log pathsLocal user account or support bundle leak
Compromised SecretsGuest OS administrative passwordsDomain Admin and database passwords

The vulnerability resides within the guest communication orchestration daemon (Veeam.Backup.GuestInteraction.exe).

CVE-2026-58070 Credential Leakage Flow:
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Job Triggered with Application-Aware Processing β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ VBR initiates WMI/RPC authentication
β”‚ Command: GuestAgent.exe -u "DOMAIN\Admin" -p "SecretP@ssword!"
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Verbose Logging Subsystem (Debug Mode) β”‚
β”‚ β€’ Full command invocation written to GuestAgent.log β”‚
β”‚ β€’ Regex redaction failure misses inline password β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Plaintext write to disk
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ C:\ProgramData\Veeam\Backup\Job_AD\Guest.log β”‚
β”‚ β€’ Readable by local non-admin users β”‚
β”‚ β€’ Instant credential harvesting β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

When verbose logging is enabled or when running the Collect Logs wizard, the logging engine failed to redact inline password arguments passed to guest testing utilities.


index=wineventlog EventCode=4663
ObjectName="*\\ProgramData\\Veeam\\Backup\\*"
ProcessName NOT IN ("*\\Veeam.Backup.Service.exe", "*\\Veeam.Backup.Manager.exe", "*\\VeeamGuestAgent.exe")
| table _time SubjectUserName ObjectName ProcessName AccessMask

  1. Apply Vendor Patch: Install the cumulative hotfix issued by Veeam Software.
  2. Purge Historical Logs: Delete historical log directories in %ProgramData%\Veeam\Backup\ created prior to patching to remove stored credentials.
  3. Rotate Guest Credentials: Perform immediate credential rotation for all accounts stored in the Veeam Credentials Manager used for guest processing.
  4. Harden Filesystem ACLs: Lock down NTFS permissions on %ProgramData%\Veeam\Backup\ to SYSTEM and Administrators only.