The vulnerability, designated CVE-2025-59470, has a CVSS score of 9.0. According to a Veeam security advisory, this vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
The vulnerability was discovered during Veeam’s own internal testing and affects versions 13.0.1.180 and earlier.
In addition to CVE-2025-59470, Veeam also addresses two other vulnerabilities that could allow remote code execution: CVE-2025-55125 and CVE-2025-59468. These vulnerabilities have a severity rating of 7.2 and 6.7, respectively. Finally, Veeam addresses CVE-2025-59469, which allowed a Backup or Tape Operator to write files as root. More information can be found here .