
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32997 is an Absolute Path Traversal vulnerability in Veeam Backup & Replication that allows an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication servers. The vulnerability affects Veeam Backup & Replication version 13 ≤ 13.0.1 on Linux. It was published on May 28, 2026, with the CVE assigned by HackerOne. It carries a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, Veeam KB4852).
The root cause is classified as CWE-36 (Absolute Path Traversal), where the application fails to properly neutralize absolute path sequences in user-supplied input, allowing an attacker to write files outside of intended restricted directories (GitHub Advisory). The attack vector is network-based with low attack complexity and no attack requirements beyond possessing a valid Backup Administrator account — no user interaction is required. The precondition for exploitation is authenticated access with the Backup Administrator role on a Linux-based Veeam Backup & Replication server. No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation allows an authenticated Backup Administrator to write arbitrary files to any location on the Linux-based Veeam Backup & Replication server, which can be leveraged to achieve remote code execution or full system compromise. The CVSS v4.0 scoring reflects high impact to confidentiality, integrity, and availability of the vulnerable system. An attacker could overwrite critical system files, plant malicious scripts, or establish persistence, potentially enabling lateral movement within the backup infrastructure (GitHub Advisory, Veeam KB4852).
No public proof-of-concept exploit or evidence of in-the-wild exploitation has been confirmed as of the time of publication (Feedly). The EPSS score is approximately 0.04–0.052%, placing it in the 17th percentile for exploitation likelihood within 30 days. The CVE status is listed as "Deferred" and it is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with the Backup Administrator role, which limits the attack surface compared to unauthenticated vulnerabilities.
/etc/cron.d/malicious or /root/.ssh/authorized_keys) as the target file write destination, bypassing any intended directory restrictions./etc/cron.d/, /root/.ssh/, /etc/passwd, /etc/sudoers, or web-accessible directories; file timestamps inconsistent with normal administrative activity.curl/wget downloads, or new cron job executions; new SSH sessions originating from the Veeam server itself.Veeam has released a patch addressing this vulnerability; users should apply the update referenced in Veeam KB4852 as the primary remediation step. As interim workarounds, organizations should restrict the Backup Administrator role to only users who strictly require it, implement network segmentation to limit access to the Veeam Backup & Replication server, and deploy file integrity monitoring on critical Linux system directories. Monitoring for unauthorized file system changes and reviewing Backup Administrator account activity are also recommended until patching is complete (Veeam KB4852, GitHub Advisory).
Heise reported on the vulnerability as part of broader Veeam Backup & Replication security update coverage, noting both Linux and Windows vulnerabilities in the same release (Heise). SecurityOnline.info also covered the Veeam security patches in a dedicated article (SecurityOnline). The Hacker News included the vulnerability in its weekly security recap, grouping it with other notable Linux flaws (The Hacker News). Community discussion on platforms such as Mastodon/VulDB noted the path traversal classification and the authenticated-only attack surface.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."