CVE-2026-64633

CRITICAL

Veeam One < 13.0.2 - Improper Control of Generation of Code ('Code Injection')

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-64633. PoCs published by tfawnies.

AI-analyzed exploit summary This repository contains detailed technical documentation of the CVE-2026-64633 exploit chain (CRLF injection leading to WHM root access) and version detection scripts, but no actual exploit code. It includes tracking pixels and reporting URLs to trapwatch.io, suggesting it is designed to monitor security researchers' behavior rather than provide a functional PoC.

Description

A vulnerability allowing remote unauthenticated code execution on the agent host.

Exploits (1)

github SUSPICIOUS
by tfawnies · poc
https://github.com/tfawnies/CVE-2026-64633

This repository contains detailed technical documentation of the CVE-2026-64633 exploit chain (CRLF injection leading to WHM root access) and version detection scripts, but no actual exploit code. It includes tracking pixels and reporting URLs to trapwatch.io, suggesting it is designed to monitor security researchers' behavior rather than provide a functional PoC.

Classification
Suspicious 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: cPanel/WHM versions ≤ 11.110.0.96, 11.118.0.62, 11.126.0.53, 11.132.0.28, 11.134.0.19, 11.136.0.4
No auth needed
Prerequisites: Network access to WHM port (2087) · Vulnerable cPanel/WHM version
mistral-large-3 · analyzed Aug 06, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v4 10.0
EPSS 0.0034
EPSS Percentile 26.2%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
Veeam/ONE < 13.0.2
Published Aug 04, 2026
Tracked Since Aug 04, 2026