SB2026080468 - Multiple vulnerabilities in Veeam Service Provider Console



SB2026080468 - Multiple vulnerabilities in Veeam Service Provider Console

Published: August 4, 2026

Security Bulletin ID SB2026080468
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Improper Authentication (CVE-ID: CVE-2026-58073)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to impersonate a managed agent and obtain that agent's credentials.

The vulnerability exists due to improper authentication in the managed agent authentication mechanism when handling agent connections. A remote attacker can impersonate a managed agent to impersonate a managed agent and obtain that agent's credentials.


2) Improper access control (CVE-ID: CVE-2026-58072)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in the management server file handling functionality when processing file write operations. A remote user can write arbitrary files on the management server to execute arbitrary code.

Exploitation requires the ability to perform authenticated actions.


3) Resource exhaustion (CVE-ID: CVE-2026-58067)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the host memory management functionality when handling requests. A remote attacker can send a sequence of requests to exhaust host memory and cause a denial of service.


4) Improper access control (CVE-ID: CVE-2026-58071)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access the proxied appliance API as Portal Administrator.

The vulnerability exists due to improper access control in the proxied appliance API when an administrator session has just begun. A remote attacker can send a crafted request during a short time window to access the proxied appliance API as Portal Administrator.

Exploitation is limited to a short window after an administrator session begins.


Remediation

Install update from vendor's website.