CVE-2024-29855 is an authentication bypass vulnerability in Veeam Recovery Orchestrator caused by a hard-coded JWT signing secret embedded in the product configuration. The application uses this static secret to generate and validate HS256-signed JSON Web Tokens for web UI authentication. Because the secret is fixed and recoverable, an unauthenticated attacker can forge authentication tokens that appear valid to the application. The vulnerable authentication flow also checks whether a presented token matches an entry already present in the product’s in-memory authorization token store, so exploitation is not limited to arbitrary token creation alone. Successful exploitation therefore depends on crafting a forged token that matches the username, role, and timing characteristics of an active session token already issued by the application. Affected versions include Veeam Recovery Orchestrator 7.0.0.337 and version ranges reported as earlier than 7.0.0.379 and from 7.1 before 7.1.0.230.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept exploit for CVE-2024-29855, an authentication bypass vulnerability in Veeam Recovery Orchestrator. The main file, CVE-2024-29855.py, is a Python script that forges JWT tokens using a hardcoded secret and attempts to authenticate to the /api/v0/Login/GetInitData endpoint on a target Veeam Recovery Orchestrator instance. The script takes parameters for the target URL, username, and a time range, and uses multithreading to spray tokens over the specified time window. If successful, it retrieves session/user data as an authenticated user, demonstrating the authentication bypass. The README.md provides background, usage instructions, affected versions, and mitigation advice. The exploit targets network-accessible Veeam Recovery Orchestrator instances running vulnerable versions and does not include post-authentication payloads or weaponization, making it a POC. The only code file is the exploit script, and the only endpoints of interest are the Veeam API and related documentation URLs.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass vulnerability in Veeam Recovery Orchestrator caused by a hardcoded JWT secret, allowing an unauthenticated attacker to forge valid tokens and access the VRO web UI, subject to conditions described in the advisory such as knowledge of username/role and an active session token.
A hard-coded JWT secret in Veeam Recovery Orchestrator that can enable authentication bypass.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.