CVE-2022-26503

HIGH

Veeam Agent for Windows <5.x - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-26503. PoCs published by sinsinology.

AI-analyzed exploit summary The repository provides a detailed analysis of CVE-2022-26503, a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows due to improper deserialization. It includes patch analysis, process inspection, and a proof-of-concept demonstration.

Description

Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.

Exploits (1)

nomisec WRITEUP 11 stars
by sinsinology · poc
https://github.com/sinsinology/CVE-2022-26503

The repository provides a detailed analysis of CVE-2022-26503, a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows due to improper deserialization. It includes patch analysis, process inspection, and a proof-of-concept demonstration.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Veeam Agent for Microsoft Windows
No auth needed
Prerequisites: Local access to the target system · Veeam Agent for Microsoft Windows installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://veeam.com
Vendor Advisory x_refsource_misc
https://www.veeam.com/kb4289

Scores

CVSS v3 7.8
EPSS 0.0068
EPSS Percentile 47.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (5)
veeam/veeam 2.0
veeam/veeam 2.1
veeam/veeam 2.2
veeam/veeam 3.0.2
veeam/veeam 4.0.0 - 4.0.2.2208
Published Mar 17, 2022
Tracked Since Feb 18, 2026