CVE-2026-32996: Veeam Agent Named-Pipe Flaw Lets Local Users Become SYSTEM
Overview
CVE-2026-32996 is a high-severity privilege escalation vulnerability in Veeam Agent for Microsoft Windows. A low-privileged local user can abuse the product's endpoint backup service to execute commands as NT AUTHORITY\SYSTEM. The flaw is rated 7.3 (High) under CVSS v4 and is reported to be exploited in the wild, with public proof-of-concept code now available.
Mechanism and exploitation conditions
The defect lives in the Veeam Endpoint Backup service and its handling of elevated client sessions over the local gRPC named pipe \.\pipe\Veeam\VAW\ServiceConnectionPipe. When the service accepts a client session, it caches an elevated administrator principal against a session UID that the client controls. That UID is not bound to the requesting user or connection, so a different, unprivileged process can present the same identifier and inherit the elevated context.
The practical consequence is that the sensitive session identifiers are stored insecurely. Elevated session UIDs are written to C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log, a file that standard users can read. An attacker who reads a valid UID from that log can replay it and run commands in the SYSTEM context. The published proof-of-concept demonstrates the technique by executing basic commands and writing their output to a file.
Exploitation requires local access to an affected endpoint; it does not require administrator rights to begin with. The attacker only needs the ability to read the service log and reach the named pipe.
Impact
Successful exploitation yields NT AUTHORITY\SYSTEM, the highest local privilege level on Windows. From there an attacker can disable security tooling, install persistence, harvest credentials, and move laterally. Because the affected component is a backup agent, compromised hosts may also expose backup repositories and stored recovery data.
Affected products and versions
- Product: Veeam Agent for Microsoft Windows (shipped with Veeam Backup & Replication 13)
- Affected: version 13.0.1.2067 and all earlier version 13 builds
Remediation and mitigation
Upgrade to Veeam Backup & Replication 13.0.2.29 or later, which updates the agent to the fixed build 13.0.3.1220. Apply the vendor advisory's download instructions.
If immediate patching is not possible, restrict interactive local logon to affected endpoints and limit local administrator and backup operator privileges to essential personnel. Prioritize shared servers and administrator workstations.
Sources
- SecurityOnline: Actively Exploited Veeam Agent Vulnerability PoC Disclosed
- Veeam security advisories (vendor)
- CVE-2026-32996 record
Top comments (0)