CVE-2026-21708: SQL Injection
Published Mar 12, 2026
·Updated
A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
Affected Software
1 affected component
Veeam Veeam Backup \& Replication>=12.0.0.1402<12.3.2.4465.
Event History
Mar 12, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionWeakness
News Published
via BleepingComputer·04:59 PM
News Published
via BleepingComputer·05:00 PM
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21708?
CVE-2026-21708 has a critical severity score of 9.9.
2
How do I fix CVE-2026-21708?
To mitigate CVE-2026-21708, it is recommended to apply the latest security patches provided by Veeam.
3
What type of attack does CVE-2026-21708 enable?
CVE-2026-21708 enables remote code execution (RCE) attacks as the postgres user.
4
Which software is affected by CVE-2026-21708?
CVE-2026-21708 affects Veeam Backup & Replication software.
5
What is the primary vulnerability type for CVE-2026-21708?
The primary vulnerability type for CVE-2026-21708 is SQL Injection.