CRITICAL🇵🇱 Wersja polska

CVE-2026-21671

CVSS 9.1v3.1pub. 2026-03-12upd. 2026-05-10

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

🤖 AI Analysis
How it works

A vulnerability classified as CWE-94 (improper control of code generation) and CWE-693 (protection mechanism failure) allows an attacker with Backup Administrator role privileges to upload or execute malicious code in the context of a high availability deployment. The attack is possible remotely over the network without requiring user interaction on the victim's side. The elevated scope (Scope: Changed) indicates that the impact of the attack may extend beyond the directly vulnerable component.

Impact

An attacker can gain full control over the system — including complete access to stored backup data and the ability to modify or destroy data (high confidentiality, integrity, and availability). In HA environments, the impact may affect multiple cluster nodes.

Mitigation & patch

Apply patches available from the vendor according to the references: https://www.veeam.com/kb4831. Additionally, it is recommended to restrict access to the Backup Administrator role only to trusted and necessary accounts, and to monitor the activity of privileged users in HA environments.

Who is affected

Veeam Backup & Replication in high availability (HA) configurations. Specific affected versions are indicated in the vendor references: https://www.veeam.com/kb4831

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Veeam Backup \& Replication

    APP
    Veeam
    13.0.0.496 – 13.0.1.1071
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-40711CRITICAL9.8⚠ KEVPL ✓same product

Krytyczne RCE przez deserialization w Veeam Backup & Replication

CVE-2022-26501CRITICAL9.8⚠ KEVPL ✓same product

Veeam Backup & Replication — nieprawidłowa kontrola dostępu (RCE bez uwierzytelnienia)

CVE-2026-21667CRITICAL9.9PL ✓same product

RCE w Veeam Backup & Replication dla uwierzytelnionego użytkownika domenowego

CVE-2026-21666CRITICAL9.9PL ✓same product

RCE dla uwierzytelnionego użytkownika domenowego w Veeam Backup & Replication

CVE-2026-21669CRITICAL9.9PL ✓same product

RCE w Veeam Backup & Replication dla uwierzytelnionych użytkowników domenowych