CVE-2026-58071

Veeam · Service Provider Console

An unauthenticated vulnerability in the Veeam Service Provider Console allows unauthorized access to the proxied appliance API as a Portal Administrator during a narrow session window.

Executive summary

A critical authentication bypass vulnerability in the Veeam Service Provider Console allows unauthenticated attackers to gain administrative API access, posing a severe risk of unauthorized system control.

Vulnerability

This is a missing authentication flaw (CWE-306) within the proxied appliance API. An unauthenticated attacker can exploit this during a specific timing window immediately following the initiation of an administrator session to impersonate a Portal Administrator.

Business impact

Successful exploitation allows an attacker to interact with the API with the privileges of a Portal Administrator, which could lead to full system compromise or unauthorized management of customer environments. Given the CVSS score of 8.2, this vulnerability represents a high risk to operational integrity and data security, necessitating immediate attention.

Remediation

Immediate Action: Upgrade to Veeam Service Provider Console version 9.3 or later as specified in the vendor advisory.

Proactive Monitoring: Audit API access logs for anomalous requests or unauthorized administrative actions that occur shortly after legitimate administrator sessions begin.

Compensating Controls: Implement strict network access controls to restrict access to the appliance API to trusted management subnets until patching is completed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The potential for unauthenticated administrative access makes this a high priority for remediation. Administrators should verify their current version and apply the vendor-provided update immediately to eliminate this exposure.