Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Critical

Remote Code Execution in Veeam Backup & Replication Backup Viewer Context

IdentifiersCVE-2026-21708

CVE-2026-21708 is a critical vulnerability in Veeam Backup & Replication that allows a user assigned the Backup Viewer role to achieve remote code execution in the context of the product’s internal PostgreSQL account (postgres). The provided content states that the issue is network-exploitable with low attack complexity, requires low privileges, and does not require user interaction (CVSS v3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). The affected product line includes Veeam Backup & Replication 12.3.2.4165 and all earlier version 12 builds, and the issue was also fixed in version 13.0.1.2067. The specific vulnerable function or code path is not identified in the provided material.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows a low-privileged authenticated user with Backup Viewer permissions to execute code remotely as the internal postgres user on the Veeam Backup & Replication system. Given the listed CVSS impacts and scope change, exploitation can result in high-impact compromise of confidentiality, integrity, and availability. In practice, this may enable access to or manipulation of backup-related data and services hosted through the PostgreSQL-backed application components, and can provide a foothold for further compromise of backup infrastructure.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by strictly limiting assignment of the Backup Viewer role, restricting network access to Veeam Backup & Replication management interfaces to only trusted administrative hosts and users, and monitoring for suspicious activity involving low-privileged backup accounts and PostgreSQL-related process execution. Because Veeam warned that attackers may reverse-engineer the patch to target unpatched systems, unpatched internet-exposed or broadly reachable deployments should be treated as high risk. No vendor-provided workaround beyond upgrading is described in the provided content.

Remediation

Patch, then assume compromise.

Upgrade Veeam Backup & Replication to a fixed release. The provided content states that Veeam addressed CVE-2026-21708 in version 12.3.2.4465 for affected version 12 deployments, and also fixed it in version 13.0.1.2067. Organizations running 12.3.2 builds 12.3.2.3617 or 12.3.2.4165 can apply the dedicated patch referenced by Veeam KB4830/KB4831, while organizations on 12.3.1 or earlier should upgrade using the full installation ISO to 12.3.2.4465. Veeam advised administrators to apply the patch immediately.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
AnyBackup Viewerapplication
Veeam SoftwareBackup & Replicationapplication
Veeam SoftwareVeeam Backup & Replicationapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity8

Community discussion across Reddit, Mastodon, and other social sources.