Threat Advisory

Veeam Service Provider Console Flaws Enable Credential Theft and Remote Code Execution

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability identified as CVE-2026-58073 with a CVSS score of 9.8 has been discovered in the Veeam Service Provider Console, allowing unauthenticated attackers to steal sensitive information and execute arbitrary code on vulnerable systems. This flaw enables remote code execution, which can lead to significant business disruption and potential financial loss due to unauthorized access to sensitive data. The vulnerability is a result of an insecure implementation that allows attackers to bypass authentication mechanisms, thereby gaining unrestricted access to the system. As a consequence, organizations using the Veeam Service Provider Console are at risk of experiencing severe security breaches if they fail to address this issue promptly.

RECOMMENDATIONS:

  • We recommend you to update Veeam Service Provider Console to the latest available version.
  • We recommend you to apply security updates for Veeam Service Provider Console.

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability identified as CVE-2026-58073 with a CVSS score of 9.8 has been discovered in the Veeam Service Provider Console, allowing unauthenticated attackers to steal sensitive information and execute arbitrary code on vulnerable systems. This flaw enables remote code execution, which can lead to significant business disruption and potential financial loss due to unauthorized access to sensitive data. The vulnerability is a result of an insecure implementation that allows attackers to bypass authentication mechanisms, thereby gaining unrestricted access to the system. As a consequence, organizations using the Veeam Service Provider Console are at risk of experiencing severe security breaches if they fail to address this issue promptly.

RECOMMENDATIONS:

  • We recommend you to update Veeam Service Provider Console to the latest available version.
  • We recommend you to apply security updates for Veeam Service Provider Console.

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu