CVE-2026-21669
Modified Modified - Updated After Analysis

Authenticated Remote Code Execution Vulnerability in Backup Server

Vulnerability report for CVE-2026-21669, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-03-12

Last updated on: 2026-05-10

Assigner: HackerOne

Description

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-03-12
Last Modified
2026-05-10
Generated
2026-07-27
AI Q&A
2026-03-12
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
veeam veeam_backup_&_replication From 13.0.0.496 (inc) to 13.0.1.2067 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-21669 is a critical security vulnerability found in Veeam Backup & Replication software versions 13.0.1.1071 and earlier 13.x builds. It allows an authenticated domain user to execute remote code on the Windows-based Backup Server, which means that someone with valid domain credentials can run arbitrary code remotely on the backup server.

This vulnerability has a very high severity score of 9.9 out of 10 according to the CVSS v3.1 rating, indicating it poses a severe security risk.

The issue was discovered during internal testing by Veeam and has been fixed in version 13.0.1.2067.

Detection Guidance

I don't know

Impact Analysis

This vulnerability can have serious impacts because it allows an authenticated domain user to perform remote code execution on the backup server.

  • An attacker with valid domain credentials could run arbitrary code remotely, potentially taking full control of the backup server.
  • This could lead to unauthorized access, data theft, data corruption, or disruption of backup services.
  • Since backup servers often contain critical data and system backups, compromising them could severely affect business continuity and data recovery.
Compliance Impact

I don't know

Mitigation Strategies

The immediate step to mitigate this vulnerability is to update Veeam Backup & Replication to version 13.0.1.2067 or later, as this version contains the fix for CVE-2026-21669.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21669. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart