Improper access control in Veeam Service Provider Console - CVE-2026-58071
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to access the proxied appliance API as Portal Administrator.
The vulnerability exists due to improper access control in the proxied appliance API when an administrator session has just begun. A remote attacker can send a crafted request during a short time window to access the proxied appliance API as Portal Administrator.
Exploitation is limited to a short window after an administrator session begins.