CVE-2025-59470
Unknown
Unknown - Not Provided
Remote Code Execution via Malicious Parameters in PostgreSQL Backup Operator
Publication date: 2026-01-08
Last updated on: 2026-01-08
Assigner: HackerOne
Description
Description
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| veeam | backup_and_replication | to 13.0.1.1071 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |