Junglewise Threat Intelligence

CVE-2026-21669: A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

CVE-2026-21669 · Severity: critical · CVSS 9.9 · Published 2026-03-12

Executive brief

Veeam Backup & Replication is a data protection solution used to back up, restore, and replicate virtual and physical machines. A critical vulnerability allows a user with basic domain credentials to execute malicious code on the backup server. This could lead to a total compromise of the backup infrastructure, potentially allowing an attacker to delete backups, steal sensitive data, or deploy ransomware across the environment.

Technical details

A remote code execution (RCE) vulnerability exists in Veeam Backup & Replication due to improper control of code generation (CWE-94). The flaw allows an authenticated domain user to execute arbitrary commands on the Backup Server with high privileges. The attack vector is over the network and requires low-privileged authentication but no user interaction. Successful exploitation results in a full system compromise (Confidentiality, Integrity, and Availability impact) and allows the attacker to escape the initial security scope. The issue is resolved in Veeam Backup & Replication version 13.0.1.2067.

Affected products

  • Veeam Veeam Backup & Replication 13.0.0.496 up to 13.0.1.1071

Timeline

  • 2026-03-12: disclosed
  • 2026-03-12: advisory
  • 2026-03-12: patched: Fixed in version 13.0.1.2067

References

Related threats