CVE-2026-21671: Code Injection
Published Mar 12, 2026
·Updated
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.
Affected Software
2 affected components
Veeam Backup & Replication
Veeam Veeam Backup \& Replication>=13.0.0.496<=13.0.1.1071
Event History
Mar 12, 2026
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
DescriptionSeverity
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21671?
CVE-2026-21671 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2026-21671?
To remediate CVE-2026-21671, update your Veeam Backup & Replication software to the latest version provided by Veeam.
3
Who is affected by CVE-2026-21671?
CVE-2026-21671 affects authenticated users with the Backup Administrator role in high availability deployments of Veeam Backup & Replication.
4
What types of deployments are vulnerable to CVE-2026-21671?
CVE-2026-21671 specifically targets high availability (HA) deployments of Veeam Backup & Replication.
5
Is CVE-2026-21671 an authenticated or unauthenticated vulnerability?
CVE-2026-21671 is an authenticated vulnerability, requiring user credentials to exploit.