started · updated
Veeam Agent for Windows vulnerability allows local privilege escalation
A security vulnerability in Veeam Agent for Windows, identified as CVE-2026-32996, has gained renewed attention following the release of a public exploit on GitHub. The flaw allows for local privilege escalation, enabling a user without special permissions to gain SYSTEM-level access, the highest level of authority on a Windows machine. The vulnerability has a CVSS v4 score of 7.3.
The issue affects Veeam Agent version 13.0.2.1102 and all prior versions within the 13 branch. While a patch was released by Veeam in late May 2026, many systems remain unpatched. Security firm Arctic Wolf previously indicated that the vulnerability was being actively exploited, though some reports regarding the extent of this exploitation have since been inconsistent.
To exploit the flaw, an attacker requires local access to the machine and an active administration session must be open in the agent console. The vulnerability is particularly risky on shared workstations, servers, or administrator machines where sessions may remain open for extended periods. Users are advised to update to Veeam Backup & Replication 13.0.2.29 or later to mitigate the risk.