Unintended Proxy or Intermediary in VMware Tanzu velero - #VU153048
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to missing phase validation in the "backupSyncReconciler.Reconcile()" function. A remote administrator can insert malicious exec hooks into a synced backup manifest in object storage and execute arbitrary shell commands inside target pods.