Veeam Agent Flaw CVE-2026-32996 Lets Local Users Gain SYSTEM Privileges
A high-severity privilege escalation vulnerability, CVE-2026-32996, has been discovered in Veeam Agent for Microsoft Windows, affecting version 13.0.1.2067 and earlier builds shipped with Veeam Backup & Replication 13. The flaw resides in the Veeam Endpoint Backup service, where a low-privileged local user can exploit improper session UID handling over a named pipe to inherit an elevated administrator context. Because the service logs valid session UIDs to a file readable by standard users, an attacker can replay a captured UID and execute commands as NT AUTHORITY\SYSTEM. Rated 7.3 (High) under CVSS v4, the vulnerability is reportedly being actively exploited in the wild, with public proof-of-concept code already available. Veeam has released a fix in Veeam Backup & Replication 13.0.2.29, which updates the agent to build 13.0.3.1220, and users are urged to upgrade immediately.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in