CVE-2026-21668
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
Affected (1)
Products: Veeam: Veeam Backup & Replication
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.0.0.1402 to 12.3.2.4465 |
Related CWEs
CWE-693
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
CWE-862
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
References (1)
Timeline
No history available yet.