[CIVN-2026-0399] Multiple Vulnerabilities in Veeam Service Provider Console

By Published On: August 11, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Veeam Service Provider Console


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Veeam Service Provider Console 9.2.1.33875 and all earlier version 9 builds.

Overview


Multiple vulnerabilities have been reported in Veeam Service Provider Console, which could allow an unauthenticated remote attacker to bypass authentication, arbitrary file write on the management server, cause denial of service (DoS) and gain administrative access on the targeted system.


Target Audience:

All organizations and individuals using the affected Veeam Service Provider Console.


Risk Assessment:

High risk of complete system compromise, execution of arbitrary commands, and denial of service (DoS) condition.


Impact Assessment:

Potential for Authentication bypass, arbitrary command execution, and unauthorized administrative access.


Description


Veeam Service Provider Console is a centralized management platform that enables service providers to monitor, manage, and deliver Veeam-powered backup, disaster recovery, and data protection services to multiple customers from a single console.


Multiple vulnerabilities have been reported in Veeam Service Provider Console due to missing authentication for critical function, exhaust host memory, authentication bypass using an alternate path or channel, and Improper limitation of a pathname to a restricted directory.


Successful exploitation of these vulnerabilities could allow an unauthenticated remote attacker to bypass authentication, arbitrary file write on the management server, cause denial of service (DoS) and gain administrative access on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://www.veeam.com/kb4893



Vendor Information


Veeam

https://www.veeam.com/kb4893


References


 

https://www.veeam.com/kb4893


CVE Name

CVE-2026-58073

CVE-2026-58072

CVE-2026-58067

CVE-2026-58071




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7EIcACgkQ3jCgcSdc

ys8rTQ//UoydjXGuo0pqfmfRqD7J/vDk+3FOGHud5Xe4NW5pdU3VJf/iX2kir52J

M80ZDJg3Z89qxNumLfmlM604y/oo6jhEFH76O0Sy9Fn6TM9jUb49uA0c7D4hohQ1

5x6ic3iYoqi3fBOUXsKln3uSBU4U0CUntGrlrCvMq9cfgzclan+zsaY0DzOKniqk

X44/eszK5IvCP2JhqeOD/YM4EfalCTkzprcpdZ6ANUTJxZfR0XqyhM7LqbQn5BBP

1zovGx7J+2ek8GCosfvMLVTiWseWUNDgk/0ws2mlBH5vm6YwKJwmpFaAict4jXSw

IQI6ceP8uvo+khF/UlHoPCOSWGIiwJuvamZ+3ZByMx/luedcg/cjRvYQppL4N19z

Rqlt/tQBctLN8ovNmUwvonH0D5+dlRHfzkxQnMKuQz+QCAwx9QaYPbXi8Y9QNWaU

6pdIxVkPZjzv7nIpCPJOwhZalVzuwgZrbDlC/36BZkSEMZfCBkHZs2VDmcg+XyUu

Nsxr/Q0iRt0Eg4Riie6NUlUpqBAkX4ZenmDy4lVKXaXyR6RzFx8Iv0x/EDDqWcea

yfzT3GIJ3sGihaRdolBSw4+MP5FmvY5TBk3wPrPhplGr+x1QfyQgq45SdYslXoi8

PlCRpnUcwEICjtxrV5hf2kWSRRual17ECjqQ/XfQ3hRz48zaqzg=

=BEyh

—–END PGP SIGNATURE—–

Share this article