Improper access control in Veeam Service Provider Console - CVE-2026-58072

 

Improper access control in Veeam Service Provider Console - CVE-2026-58072

Published: August 4, 2026


Vulnerability identifier: #VU140870
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58072
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in the management server file handling functionality when processing file write operations. A remote user can write arbitrary files on the management server to execute arbitrary code.

Exploitation requires the ability to perform authenticated actions.


Affected software

Veeam Service Provider Console

How to mitigate CVE-2026-58072

Install security update from vendor's website.

Veeam Service Provider Console - update to 9.3.0.35057

External References