CVE-2024-29855
CriticalPublished
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
- Published
- Jun 11, 2024
- Updated
- Mar 27, 2025
- Assigning CNA
- hackerone
- Evidence observed
- Aug 4, 2026
Primary CVSS
9.0/ 10Critical
nvd · CVSS 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H21.6%
Moderate · next 30 days
- Percentile
- 97.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
Sources
1- CVE-2024-29855Exploit
PoC for the Veeam Recovery Orchestrator Authentication CVE-2024-29855
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.