Threat Advisory

Veeam Flaw Lets Unauthenticated Attacker Impersonate Agent and Steal Credentials

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Veeam Service Provider Console, HashiCorp's MCP server, and Django. The overall risk/impact is high due to the presence of critical flaws that can lead to remote code execution, cross-tenant credential reuse, and arbitrary file writes.

CVE-2026-58073 (CVSS 9.5 — Severity): An unauthenticated attacker can impersonate a managed agent and obtain its credentials by exploiting this vulnerability in Veeam Service Provider Console.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Veeam Service Provider Console, HashiCorp's MCP server, and Django. The overall risk/impact is high due to the presence of critical flaws that can lead to remote code execution, cross-tenant credential reuse, and arbitrary file writes.

CVE-2026-58073 (CVSS 9.5 — Severity): An unauthenticated attacker can impersonate a managed agent and obtain its credentials by exploiting this vulnerability in Veeam Service Provider Console.[emaillocker id="1283"]

CVE-2026-58072: This critical flaw is an arbitrary file write on the management server that can lead to remote code execution, requiring only a low-privilege account in Veeam Service Provider Console.

CVE-2026-58067: An unauthenticated memory-exhaustion denial of service vulnerability exists in Veeam Service Provider Console.

CVE-2026-58071: This flaw exposes the proxied appliance API as Portal Administrator during a short window after an administrator session begins in Veeam Service Provider Console.

CVE-2026-32998: a 9.4-rated remote code execution bug tied to alarm script execution.

CVE-2026-16498 (CVSS 10.0 — Severity): A cross-tenant credential-reuse bug exists in stateless HTTP mode of HashiCorp's MCP server, allowing one user's Terraform token to be reused for later users' requests.

CVE-2026-16496: This flaw is the stateful-mode version of the isolation failure, where a user who obtained another user's session ID can run tool calls with that user's Terraform client and reach resources allowed by the victim's token in HashiCorp's MCP server.

CVE-2026-14869 (CVSS 8.6 — Severity): A server-side request forgery flaw exists in HashiCorp's MCP server, allowing an unauthenticated caller to make requests on behalf of another user. These vulnerabilities collectively present a significant risk to administrators who have not applied the available fixes. Administrators should update Terraform MCP Server to version 1.1.0 or later, Veeam Service Provider Console to 9.3.0.35057, and Django to 6.0.8 or 5.2.17 as soon as possible.

CVE-2026-15307: sits in GeoDjango, the framework's geographic-data layer. Spatial lookups accepted str and dict values and passed them to GDALRaster when they appeared to represent rasters.

CVE-2026-15830: now limited to 198 collections); and.

CVE-2026-15337: Now rejecting language codes longer than 500 characters).

CVE-2026-1207: a SQL injection flaw in PostGIS raster lookups.

These vulnerabilities collectively present a significant risk to administrators who have not applied the available fixes.

RECOMMENDATIONS:

  • We recommend you to update Terraform MCP Server to version 1.1.0 or later.
  • We recommend you to update Veeam Service Provider Console to 9.3.0.35057.
  • We recommend you to update Django to version 6.0.8 or 5.2.17.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu