
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21709 is a command injection vulnerability in Veeam Backup and Replication and Veeam Software Appliance that allows a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement. It was published on April 17, 2026, and affects Veeam Backup and Replication versions 12 prior to 12.3.2, and Software Appliance versions 13 prior to 13.0.1. The vulnerability carries a CVSS v3.1 base score of 6.7 (Medium) (GitHub Advisory, ENISA EUVD).
The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — Command Injection), where the affected Veeam product fails to properly sanitize input used in constructing system commands, enabling an attacker to inject malicious elements (GitHub Advisory). Exploitation requires local access and administrator-level privileges on the affected Windows system, making the attack vector local with low complexity and no user interaction required. By exploiting this flaw, an attacker can bypass Windows Driver Signature Enforcement (DSE), a security mechanism that prevents unsigned or untrusted kernel drivers from loading (ENISA EUVD). No public proof-of-concept code has been identified at this time.
Successful exploitation allows a local administrator to load unsigned or malicious kernel-mode drivers, effectively circumventing a core Windows security control. This can lead to kernel-level system compromise, persistent malware installation (such as rootkits), privilege escalation beyond the administrator context, and full confidentiality, integrity, and availability impact on the affected host (GitHub Advisory, ENISA EUVD). Given that Veeam Backup and Replication systems often have broad access to backup data and connected infrastructure, a compromised host could facilitate lateral movement or data exfiltration across the environment.
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of this report (GitHub Advisory). The vulnerability has an EPSS score of approximately 0.011% (1st percentile), indicating a low near-term probability of exploitation (GitHub Advisory). It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for local administrator access, which limits the attacker pool but does not eliminate risk in environments with shared or compromised admin credentials.
Veeam has released patches addressing this vulnerability. Users should upgrade Veeam Backup and Replication to version 12.3.2 or later, and Veeam Software Appliance to version 13.0.1 or later (Veeam KB4830, Veeam KB4831). As interim mitigations, organizations should restrict administrative privileges to trusted personnel only, implement application whitelisting to prevent unauthorized driver installation, and monitor Windows Driver Signature Enforcement logs for bypass attempts. Applying the vendor patch is the recommended and definitive remediation.
The vulnerability was disclosed via HackerOne and published to the GitHub Advisory Database on April 17, 2026, with a moderate severity rating (GitHub Advisory). Automated tracking services including Tenable, VulDB, and CIRCL have indexed the vulnerability, but no notable independent researcher commentary or significant media coverage has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."