CVE-2026-64633
CRITICALVeeam One < 13.0.2 - Improper Control of Generation of Code ('Code Injection')
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2026-64633. PoCs published by tfawnies.
AI-analyzed exploit summary This repository contains detailed technical documentation of the CVE-2026-64633 exploit chain (CRLF injection leading to WHM root access) and version detection scripts, but no actual exploit code. It includes tracking pixels and reporting URLs to trapwatch.io, suggesting it is designed to monitor security researchers' behavior rather than provide a functional PoC.
Description
A vulnerability allowing remote unauthenticated code execution on the agent host.
Exploits (1)
This repository contains detailed technical documentation of the CVE-2026-64633 exploit chain (CRLF injection leading to WHM root access) and version detection scripts, but no actual exploit code. It includes tracking pixels and reporting URLs to trapwatch.io, suggesting it is designed to monitor security researchers' behavior rather than provide a functional PoC.
References (1)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X