Cyber Posture

CVE-2026-21670

High

Published: 12 March 2026

Published
12 March 2026
Modified
10 May 2026
KEV Added
Patch
CVSS Score 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS Score 0.0004 11.4th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-21670 is a high-severity Insufficiently Protected Credentials (CWE-522) vulnerability in Veeam Veeam Backup \& Replication. Its CVSS base score is 7.7 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Unsecured Credentials (T1552); ranked at the 11.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 IA-5 (Authenticator Management) and SI-2 (Flaw Remediation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Unsecured Credentials (T1552) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

IA-5 mandates protecting authenticator content from unauthorized disclosure and modification, directly addressing the insufficient protection of saved SSH credentials accessible to low-privileged users.

prevent

SI-2 requires timely identification, reporting, and correction of system flaws, enabling patching of the specific vulnerability that allows extraction of SSH credentials.

prevent

AC-6 enforces least privilege, limiting low-privileged users' access to sensitive credential storage and mitigating unauthorized extraction.

MITRE ATT&CK Enterprise TechniquesAI

T1552 Unsecured Credentials Credential Access
Adversaries may search compromised systems to find and obtain insecurely stored credentials.
T1552.004 Private Keys Credential Access
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials.
Why these techniques?

Directly enables extraction of insufficiently protected saved SSH credentials (CWE-522), mapping to unsecured credentials access and private key retrieval.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

A vulnerability allowing a low-privileged user to extract saved SSH credentials.

Deeper analysisAI

CVE-2026-21670 is a vulnerability that allows a low-privileged user to extract saved SSH credentials, classified under CWE-522 (Insufficiently Protected Credentials). It affects Veeam software, as detailed in the vendor's knowledge base article. The vulnerability received a CVSS v3.1 base score of 7.7 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), indicating high severity due to network accessibility, low attack complexity, low privilege requirements, no user interaction, changed scope, and high confidentiality impact.

A low-privileged user (PR:L) can exploit this vulnerability remotely over the network (AV:N) with low complexity and no user interaction. Successful exploitation enables the attacker to achieve high confidentiality impact (C:H) by extracting saved SSH credentials, potentially leading to unauthorized access to other systems or resources configured via those credentials.

The Veeam knowledge base article at https://www.veeam.com/kb4831 provides details on mitigation and patches for this vulnerability. Security practitioners should consult this advisory for specific remediation steps, such as applying the recommended updates.

Details

CWE(s)

Affected Products

veeam
veeam backup \& replication
13.0.0.496 — 13.0.1.1071

CVEs Like This One

CVE-2025-59468Same product: Veeam Veeam Backup \& Replication
CVE-2026-21666Same product: Veeam Veeam Backup \& Replication
CVE-2026-21671Same product: Veeam Veeam Backup \& Replication
CVE-2025-59470Same product: Veeam Veeam Backup \& Replication
CVE-2026-21667Same product: Veeam Veeam Backup \& Replication
CVE-2026-21668Same product: Veeam Veeam Backup \& Replication
CVE-2025-59469Same product: Veeam Veeam Backup \& Replication
CVE-2026-21669Same product: Veeam Veeam Backup \& Replication
CVE-2025-48984Same product: Veeam Veeam Backup \& Replication
CVE-2025-23120Same product: Veeam Veeam Backup \& Replication

References