Improper access control in Veeam Service Provider Console - CVE-2026-58072
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the management server file handling functionality when processing file write operations. A remote user can write arbitrary files on the management server to execute arbitrary code.
Exploitation requires the ability to perform authenticated actions.