CVE-2026-58067

Veeam · Service Provider Console

Veeam Service Provider Console is susceptible to memory exhaustion, allowing an unauthenticated attacker to cause a denial of service on the host system.

Executive summary

A critical denial of service vulnerability in Veeam Service Provider Console allows unauthenticated attackers to crash the host system by exhausting available memory.

Vulnerability

The software contains a memory allocation flaw (CWE-789) where it accepts excessive size values during processing. This allows an unauthenticated remote attacker to trigger a denial of service condition by exhausting host memory.

Business impact

Successful exploitation results in total loss of service availability for the affected console, which can disrupt management operations for downstream services. The CVSS score of 8.7 highlights the severity of this risk, as it permits unauthenticated actors to remotely destabilize critical infrastructure components.

Remediation

Immediate Action: Update to Veeam Service Provider Console version 9.3 or higher as directed in the vendor's knowledge base article KB4893.

Proactive Monitoring: Monitor system resource usage, specifically memory consumption, to detect spikes that may indicate an ongoing denial of service attempt.

Compensating Controls: Deploy a Web Application Firewall or similar filtering solution to drop malformed requests that attempt to pass excessive size values to the console.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a significant risk to service continuity for managed service providers. Organizations using Veeam Service Provider Console must apply the vendor patch immediately to prevent potential remote service disruption.