Public PoC Exposes Critical Veeam Agent Privilege Escalation
A public proof-of-concept exploit for CVE-2026-32996 in Veeam Agent for Microsoft Windows up to version 13.0.1.2067 was released on September 14, 2026. A local user can escalate to NT AUTHORITY\SYSTEM by reading a session UID from a log file. The fix is Veeam Backup & Replication 13.0.2.29 or later.
- Flaw affects Veeam Agent for Windows up to 13.0.1.2067
- Attacker reads UID from Svc.VeeamEndpointBackup.log to gain SYSTEM
- Public GitHub PoC runs whoami with SYSTEM privileges
- Fix is Veeam Backup & Replication 13.0.2.29, Agent 13.0.3.1220
Read next
Security