Improper access control in Backup & Replication - CVE-2026-44963
Published: June 9, 2026
Backup & Replication
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code on the backup server.
The vulnerability exists due to improper access control in the backup server when handling requests from authenticated domain users. A remote user can send a specially crafted request to execute arbitrary code on the backup server.
Only domain-joined backup servers are vulnerable.