Junglewise Threat Intelligence

CVE-2026-21672: A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

CVE-2026-21672 · Severity: high · CVSS 8.8 · Published 2026-03-12

Technologies: Veeam Backup & Replication. Vendors: Veeam.

Executive brief

A vulnerability in Veeam Backup & Replication allows a user with low-level access to a Windows server to gain full administrative control. Veeam is a critical data protection and backup solution used to safeguard corporate data; an attacker who gains administrative rights could potentially access, modify, or delete sensitive backups. This could lead to significant data loss or provide a foothold for further attacks within the corporate network.

Technical details

A local privilege escalation vulnerability exists in Windows-based Veeam Backup & Replication servers. The flaw is categorized as CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory), suggesting that sensitive data or configuration files may be improperly secured, allowing a low-privileged local user to leverage this information to escalate their privileges. An attacker with local access and low-level permissions can achieve full system or administrative control (Scope: Changed). The vulnerability is resolved in Veeam Backup & Replication versions 12.3.2.4465 and 13.0.1.2067.

Affected products

  • Veeam Backup & Replication 12, 12.1, 12.2, 12.3, 12.3.1, 12.3.2 (prior to build 12.3.2.4465)
  • Veeam Backup & Replication 13 (prior to build 13.0.1.2067)

Timeline

  • 2026-03-12: disclosed: Initial disclosure via NVD and Veeam KB articles.
  • 2026-03-12: patched: Fixed in builds 12.3.2.4465 and 13.0.1.2067.
  • 2026-04-16: other: Veeam KB articles last modified.

References