Executive brief
Veeam Backup & Replication is a data protection solution used to back up, restore, and replicate virtual and physical machines. A vulnerability in the Linux-based software appliance version allows an authorized administrator to write files to any location on the server's file system. This could be used by a high-privileged user to modify system configurations or gain deeper control over the backup infrastructure, potentially compromising the integrity of stored data.
Technical details
A path traversal vulnerability (CWE-36) exists in the Linux-based Veeam Backup & Replication server (Veeam Software Appliance). The flaw allows an authenticated user with the 'Backup Administrator' role to bypass intended file system restrictions and write arbitrary files to the underlying operating system. While the attack requires high privileges (PR:H), it enables an attacker to achieve full impact on confidentiality, integrity, and availability of the appliance. The issue is resolved in Veeam Backup & Replication version 13.0.2.29.
Affected products
- Veeam Backup & Replication (Software Appliance) 13.0.1.2067 and all earlier version 13 builds
Timeline
- 2026-05-27: patched: Fixed in version 13.0.2.29
- 2026-05-27: advisory: Veeam KB4852 published
- 2026-05-28: disclosed: CVE-2026-32997 published to NVD