CVE-2026-58071
Veeam · Service Provider Console
An unauthenticated vulnerability in the Veeam Service Provider Console allows unauthorized access to the proxied appliance API as a Portal Administrator during a narrow session window.
Executive summary
A critical authentication bypass vulnerability in the Veeam Service Provider Console allows unauthenticated attackers to gain administrative API access, posing a severe risk of unauthorized system control.
Vulnerability
This is a missing authentication flaw (CWE-306) within the proxied appliance API. An unauthenticated attacker can exploit this during a specific timing window immediately following the initiation of an administrator session to impersonate a Portal Administrator.
Business impact
Successful exploitation allows an attacker to interact with the API with the privileges of a Portal Administrator, which could lead to full system compromise or unauthorized management of customer environments. Given the CVSS score of 8.2, this vulnerability represents a high risk to operational integrity and data security, necessitating immediate attention.
Remediation
Immediate Action: Upgrade to Veeam Service Provider Console version 9.3 or later as specified in the vendor advisory.
Proactive Monitoring: Audit API access logs for anomalous requests or unauthorized administrative actions that occur shortly after legitimate administrator sessions begin.
Compensating Controls: Implement strict network access controls to restrict access to the appliance API to trusted management subnets until patching is completed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The potential for unauthenticated administrative access makes this a high priority for remediation. Administrators should verify their current version and apply the vendor-provided update immediately to eliminate this exposure.