Junglewise Threat Intelligence

CVE-2026-21671: A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availabilit

CVE-2026-21671 · Severity: critical · CVSS 9.1 · Published 2026-03-12

Executive brief

Veeam Backup & Replication is a data protection solution used to back up and restore virtual and physical workloads. A security vulnerability in high availability deployments allows an authorized Backup Administrator to execute arbitrary commands on the system. This could lead to a complete takeover of the backup infrastructure and potential access to sensitive backed-up data.

Technical details

A remote code execution (RCE) vulnerability exists in Veeam Backup & Replication high availability (HA) deployments due to improper control of generation of code (CWE-94). The flaw is specifically present in the Veeam Software Appliance deployment type. An attacker must be authenticated with the high-privileged 'Backup Administrator' role to exploit this vulnerability. Successful exploitation allows for full system compromise with a CVSS 3.1 score of 9.1. The issue is resolved in Veeam Backup & Replication version 13.0.1.2067.

Affected products

  • Veeam Veeam Backup & Replication 13.0.0.496 through 13.0.1.1071

Timeline

  • 2026-03-12: disclosed
  • 2026-03-12: advisory
  • 2026-03-12: patched: Fixed in version 13.0.1.2067

References

Related threats