Improper access control in Backup & Replication - CVE-2026-32997
Published: May 27, 2026
Backup & Replication
Detailed vulnerability description
The vulnerability allows a remote user to write arbitrary files.
The vulnerability exists due to improper access control in the Veeam Software Appliance server when handling authenticated administrative actions. A remote privileged user can write arbitrary files to write arbitrary files.
The issue requires the Backup Administrator role on a Linux-based Veeam Backup & Replication server.