CVE-2026-32996: Privilege Escalation in Veeam Agent for Windows
A high-severity local privilege escalation, CVE-2026-32996 (CVSS v4 7.3), affects Veeam Agent for Microsoft Windows and is already exploited in the wild with public PoC code. Attackers read a cached elevated session UID from a log file and replay it to run commands as SYSTEM; the fix is Veeam Backup & Replication 13.0.2.29 with agent build 13.0.3.1220.
- CVE-2026-32996 is a local privilege escalation in Veeam Agent for Windows, CVSS v4 7.3
- Exploitation grants NT AUTHORITY\SYSTEM by replaying a session UID
- The UID is written to Svc.VeeamEndpointBackup.log, readable by standard users
- Patch: Veeam Backup & Replication 13.0.2.29, agent build 13.0.3.1220
Read next
Security