Improper access control in Veeam Service Provider Console - CVE-2026-58071

 

Improper access control in Veeam Service Provider Console - CVE-2026-58071

Published: August 4, 2026


Vulnerability identifier: #VU140872
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58071
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access the proxied appliance API as Portal Administrator.

The vulnerability exists due to improper access control in the proxied appliance API when an administrator session has just begun. A remote attacker can send a crafted request during a short time window to access the proxied appliance API as Portal Administrator.

Exploitation is limited to a short window after an administrator session begins.


Affected software

Veeam Service Provider Console

How to mitigate CVE-2026-58071

Install security update from vendor's website.

Veeam Service Provider Console - update to 9.3.0.35057

External References