Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                Note d'Information No. 2026/VULN561
_____________________________________________________________________

DATE                : 29/05/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Veeam Backup & Replication
                        versions prior to 13.0.2.29.

=====================================================================
https://www.veeam.com/kb4852
_____________________________________________________________________


Vulnerabilities Resolved in Veeam Backup & Replication 13.0.2

KB ID: 	4852
Published: 	2026-05-27
Last Modified: 	2026-05-27


All vulnerabilities documented in this article were resolved in Veeam
Backup & Replication 13.0.2.29.

Veeam Software Security Commitment
Veeam® is committed to ensuring its products protect customers from
potential risks. As part of that commitment, we operate a Vulnerability
Disclosure Program (VDP) for all Veeam products and perform extensive
internal code audits. When a vulnerability is identified, our team
promptly develops a patch to address and mitigate the risk. In line
with our dedication to transparency, we publicly disclose the
vulnerability and provide detailed mitigation information. This
approach ensures that all potentially affected customers can quickly
implement the necessary measures to safeguard their systems. It’s
important to note that once a vulnerability and its associated patch
are disclosed, attackers will likely attempt to reverse-engineer the
patch to exploit unpatched deployments of Veeam software. This
reality underscores the critical importance of ensuring that all
customers use the latest versions of our software and install all
updates and patches without delay.


Issue Details

All vulnerabilities disclosed in this article affect
Veeam Backup & Replication 13.0.1.2067 and all earlier version
13 builds.


CVE-2026-32996

A vulnerability in Veeam Agent for Microsoft Windows allows for
Local Privilege Escalation.

Severity: High
CVSS v3.1 Score: 7.3
Affected Deployment Type: Veeam Agent for Microsoft Windows
Source: Reported by Alibabas through HackerOne.


CVE-2026-32997

A vulnerability allowing an authenticated user with the Backup
Administrator role to write arbitrary files on a Linux-based
Veeam Backup & Replication server (Veeam Software Appliance).

Severity: High
CVSS v3.1 Score: 8.6
Affected Deployment Type: Veeam Software Appliance
Source: Reported by Parsa through HackerOne.


Solution

These vulnerabilities were fixed starting with the following build:

    Veeam Backup & Replication 13.0.2.29

If this KB article did not resolve your issue or you need further
assistance with Veeam software, please create a Veeam Support Case.

To submit feedback regarding this article, please click this
link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse
and press CTRL + Enter.


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




