A trio of high-severity vulnerabilities, including a critical cross-tenant bug with a perfect 10.0 CVSS score, has been disclosed in popular software tools Veeam, Terraform MCP, and Django. These flaws could allow attackers to breach sensitive systems, compromising user identities and data.
The most severe vulnerability affects Veeam Backup & Replication, a widely used backup solution for virtualized environments. A CVSS 10.0-rated cross-tenant bug allows an attacker with minimal privileges to escalate their access to other tenants within the same instance of the software. This could grant them unrestricted access to sensitive data and systems.
Veeam has confirmed that this flaw is present in all versions of Backup & Replication, including those using advanced features such as Scale-Out Backup Repository and Cloud Tier. The company has released an emergency patch to address the issue, which users are urged to apply immediately.
A separate vulnerability in Terraform MCP, a popular infrastructure-as-code tool, allows attackers to execute arbitrary code on remote servers. This flaw, rated CVSS 9.8, is present in versions up to 0.15.6 and can be exploited by an attacker with access to the Terraform configuration files. The Terraform development team has released a patch for the issue.
Meanwhile, the Django web framework has been hit with several high-severity vulnerabilities, including a CVSS 9.8-rated bug that allows attackers to bypass authentication mechanisms. This flaw affects versions up to 4.1 and can be exploited by an attacker with access to the application’s user input fields. The Django development team has released patches for all affected versions.
The combined impact of these vulnerabilities is significant, as they could potentially allow attackers to gain unauthorized access to sensitive systems and data. Identity exposure is a critical concern in modern computing environments, where multiple applications and services are often interconnected. By exploiting cross-domain privilege escalation bugs like the one in Veeam, attackers can unlock active attack paths that would be difficult or impossible to defend against.
In light of these disclosures, it’s essential for organizations using these software tools to prioritize patching and updating their systems as soon as possible. This will help prevent potential breaches and ensure the integrity of sensitive data and user identities. Users should also take this opportunity to review their security configurations and implement additional safeguards to mitigate the risk of identity exposure.
Source: The Hacker News — 2026-08-05