A vulnerability was found in Veeam ONE up to 13.0.2 and classified as problematic. The affected element is an unknown function of the component Reporter service. Such manipulation leads to improper privilege management.

This vulnerability is documented as CVE-2026-64634. The attack needs to be performed locally. There is not any exploit available.