NTLM Credential Capture via Reporter Service Account (Windows)
CVE-2026-64632 Published on August 26, 2026
A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
Weakness Type
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Products Associated with CVE-2026-64632
Want to know whenever a new CVE is published for Veeam One? stack.watch will email you.
Affected Versions
Veeam ONE:- Before and including 13.0.2 is affected.