Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-32997 |
| Alert Source | Veeam Security Advisory |
| CVE Publication Year | 2026 |
| Date Published | 2026-05-28 |
| Vendor | Veeam |
| Product | Service Provider Console / Backup & Replication |
| Vulnerability Type | Arbitrary File Write / Privilege Escalation |
| CVSS Score | 8.8 (high) |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
This vulnerability allows an attacker to perform unauthorized arbitrary file writes and potentially gain elevated privileges on vulnerable instances of Veeam Service Provider Console and Veeam Backup & Replication. Successful exploitation could result in unauthorized modification of configuration files, replacement of backup-system binaries, or takeover of the service process.
Required Actions
Promptly update the vulnerable Veeam products to the latest vendor-supported versions:
- Veeam Service Provider Console — upgrade from 9.x to 9.2.0.33215 or later
- Veeam Backup & Replication — upgrade from 13.x to 13.0.1.2067 or later
Until updates are deployed, restrict access to Veeam management interfaces to trusted administrative segments only, enforce MFA for privileged accounts, and monitor file integrity (FIM) in Veeam installation directories.
Who Is Affected?
This vulnerability affects:
- Veeam Service Provider Console versions 9.x prior to 9.2.0.33215
- Veeam Backup & Replication versions 13.x prior to 13.0.1.2067
Environments where Veeam service accounts hold broad host operating-system privileges are particularly exposed — a typical scenario in VBR installations. Privilege escalation combined with arbitrary file write allows an attacker to establish persistence and potentially fully compromise the backup server.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
