
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21667 is an improper access control vulnerability in Veeam Backup & Replication that allows an authenticated domain user to perform remote code execution (RCE) on the Backup Server. It affects versions 12.0.0.1402 through 12.3.2.4465 (exclusive) and was published on March 12, 2026. The vulnerability was assigned a CVSS v3.1 base score of 8.8 (High) by NVD, though ENISA's EU Vulnerability Database scores it at 10.0 (Critical) using a broader scope vector. A patch was made available on March 30, 2026 (Veeam KB4830).
The root cause is classified as CWE-284 (Improper Access Control), where the Backup Server fails to adequately restrict operations available to authenticated domain users. An attacker with low-privilege domain credentials can send crafted network requests to the Backup Server over the network (attack vector: Network, complexity: Low) without requiring any user interaction, triggering arbitrary code execution. No public technical write-up or proof-of-concept code detailing the specific vulnerable endpoint or payload has been identified at this time (Veeam KB4830, Feedly).
Successful exploitation grants an attacker full remote code execution on the Backup Server, resulting in high confidentiality, integrity, and availability impact. This can lead to complete compromise of the backup infrastructure — including unauthorized access to sensitive backup data, modification or deletion of backup jobs and data, and disruption of backup and recovery operations. Because backup servers typically hold credentials and data for a broad set of systems, a compromised Backup Server poses significant lateral movement risk across the enterprise (Veeam KB4830, BleepingComputer).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.30%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Veeam Backup & Replication has historically been a high-value target for ransomware groups, and the low privilege requirement makes this vulnerability attractive for threat actors (BleepingComputer, Bulwark Black).
Veeam has released version 12.3.2.4465 as the patched release; all users running versions 12.0.0.1402 through earlier 12.3.x builds should upgrade immediately (Veeam KB4830). As interim mitigations, restrict network access to the Backup Server to authorized administrators only, implement network segmentation to limit the blast radius of a potential compromise, and monitor Backup Server logs for suspicious activity originating from authenticated domain accounts. Enforce strong access control policies for all domain accounts with access to backup infrastructure.
The disclosure generated significant coverage across security media, with BleepingComputer, The Hacker News, CSO Online, and TechRadar all reporting on the broader batch of seven critical Veeam vulnerabilities patched simultaneously (BleepingComputer, The Hacker News). Security researchers and community members on Reddit and Mastodon highlighted the risk given Veeam's historical targeting by ransomware operators (Reddit). Ireland's NCSC issued an advisory referencing the related CVE-2026-21666 vulnerability in the same patch batch, underscoring the urgency of patching (NCSC Ireland). Bulwark Black specifically noted that ransomware groups were paying attention to this cluster of Veeam flaws (Bulwark Black).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."