CVE-2026-32997
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

CVE-2026-32997 is an Absolute Path Traversal vulnerability in Veeam Backup & Replication that allows an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication servers. The vulnerability affects Veeam Backup & Replication version 13 ≤ 13.0.1 on Linux. It was published on May 28, 2026, with the CVE assigned by HackerOne. It carries a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, Veeam KB4852).

Technical details

The root cause is classified as CWE-36 (Absolute Path Traversal), where the application fails to properly neutralize absolute path sequences in user-supplied input, allowing an attacker to write files outside of intended restricted directories (GitHub Advisory). The attack vector is network-based with low attack complexity and no attack requirements beyond possessing a valid Backup Administrator account — no user interaction is required. The precondition for exploitation is authenticated access with the Backup Administrator role on a Linux-based Veeam Backup & Replication server. No public proof-of-concept code has been identified at this time (Feedly).

Impact

Successful exploitation allows an authenticated Backup Administrator to write arbitrary files to any location on the Linux-based Veeam Backup & Replication server, which can be leveraged to achieve remote code execution or full system compromise. The CVSS v4.0 scoring reflects high impact to confidentiality, integrity, and availability of the vulnerable system. An attacker could overwrite critical system files, plant malicious scripts, or establish persistence, potentially enabling lateral movement within the backup infrastructure (GitHub Advisory, Veeam KB4852).

Exploitability

No public proof-of-concept exploit or evidence of in-the-wild exploitation has been confirmed as of the time of publication (Feedly). The EPSS score is approximately 0.04–0.052%, placing it in the 17th percentile for exploitation likelihood within 30 days. The CVE status is listed as "Deferred" and it is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with the Backup Administrator role, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify Linux-based Veeam Backup & Replication servers (version 13 ≤ 13.0.1) accessible over the network, using network scanning tools or internal asset inventories.
  2. Obtain Credentials: Acquire valid credentials for an account with the Backup Administrator role, either through phishing, credential theft, or insider access.
  3. Authenticate: Log in to the Veeam Backup & Replication management interface or API using the obtained Backup Administrator credentials.
  4. Craft Malicious Request: Construct a request that exploits the absolute path traversal flaw (CWE-36) by supplying an absolute path (e.g., /etc/cron.d/malicious or /root/.ssh/authorized_keys) as the target file write destination, bypassing any intended directory restrictions.
  5. Write Arbitrary File: Submit the crafted request to write a malicious payload — such as a cron job, SSH authorized key, or web shell — to a sensitive system location.
  6. Achieve Code Execution: Trigger the written payload (e.g., wait for cron execution or use the planted SSH key) to gain remote code execution or persistent access on the server (GitHub Advisory, Veeam KB4852).

Indicators of compromise

  • Network: Unusual or unexpected API/management interface requests from Backup Administrator accounts, especially those containing absolute path strings in file-related parameters; connections to the Veeam server from unfamiliar IP addresses.
  • File System: Unexpected new or modified files in sensitive directories such as /etc/cron.d/, /root/.ssh/, /etc/passwd, /etc/sudoers, or web-accessible directories; file timestamps inconsistent with normal administrative activity.
  • Logs: Veeam application logs showing file write operations to paths outside expected backup storage directories; authentication events for Backup Administrator accounts at unusual times or from unusual sources.
  • Process: Unexpected processes spawned by the Veeam service account, such as reverse shells, curl/wget downloads, or new cron job executions; new SSH sessions originating from the Veeam server itself.

Mitigation and workarounds

Veeam has released a patch addressing this vulnerability; users should apply the update referenced in Veeam KB4852 as the primary remediation step. As interim workarounds, organizations should restrict the Backup Administrator role to only users who strictly require it, implement network segmentation to limit access to the Veeam Backup & Replication server, and deploy file integrity monitoring on critical Linux system directories. Monitoring for unauthorized file system changes and reviewing Backup Administrator account activity are also recommended until patching is complete (Veeam KB4852, GitHub Advisory).

Community reactions

Heise reported on the vulnerability as part of broader Veeam Backup & Replication security update coverage, noting both Linux and Windows vulnerabilities in the same release (Heise). SecurityOnline.info also covered the Veeam security patches in a dedicated article (SecurityOnline). The Hacker News included the vulnerability in its weekly security recap, grouping it with other notable Linux flaws (The Hacker News). Community discussion on platforms such as Mastodon/VulDB noted the path traversal classification and the authenticated-only attack surface.

Additional resources


SourceThis report was generated using AI

Related Veeam Backup & Replication vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21708CRITICAL9.9
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMar 12, 2026
CVE-2026-44963CRITICAL9.4
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesJun 09, 2026
CVE-2026-32997HIGH8.6
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-32996HIGH7.3
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-21709MEDIUM6.7
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesApr 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management