
[CIVN-2026-0399] Multiple Vulnerabilities in Veeam Service Provider Console
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Veeam Service Provider Console
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Veeam Service Provider Console 9.2.1.33875 and all earlier version 9 builds.
Overview
Multiple vulnerabilities have been reported in Veeam Service Provider Console, which could allow an unauthenticated remote attacker to bypass authentication, arbitrary file write on the management server, cause denial of service (DoS) and gain administrative access on the targeted system.
Target Audience:
All organizations and individuals using the affected Veeam Service Provider Console.
Risk Assessment:
High risk of complete system compromise, execution of arbitrary commands, and denial of service (DoS) condition.
Impact Assessment:
Potential for Authentication bypass, arbitrary command execution, and unauthorized administrative access.
Description
Veeam Service Provider Console is a centralized management platform that enables service providers to monitor, manage, and deliver Veeam-powered backup, disaster recovery, and data protection services to multiple customers from a single console.
Multiple vulnerabilities have been reported in Veeam Service Provider Console due to missing authentication for critical function, exhaust host memory, authentication bypass using an alternate path or channel, and Improper limitation of a pathname to a restricted directory.
Successful exploitation of these vulnerabilities could allow an unauthenticated remote attacker to bypass authentication, arbitrary file write on the management server, cause denial of service (DoS) and gain administrative access on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.veeam.com/kb4893
Vendor Information
Veeam
https://www.veeam.com/kb4893
References
https://www.veeam.com/kb4893
CVE Name
CVE-2026-58073
CVE-2026-58072
CVE-2026-58067
CVE-2026-58071
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7EIcACgkQ3jCgcSdc
ys8rTQ//UoydjXGuo0pqfmfRqD7J/vDk+3FOGHud5Xe4NW5pdU3VJf/iX2kir52J
M80ZDJg3Z89qxNumLfmlM604y/oo6jhEFH76O0Sy9Fn6TM9jUb49uA0c7D4hohQ1
5x6ic3iYoqi3fBOUXsKln3uSBU4U0CUntGrlrCvMq9cfgzclan+zsaY0DzOKniqk
X44/eszK5IvCP2JhqeOD/YM4EfalCTkzprcpdZ6ANUTJxZfR0XqyhM7LqbQn5BBP
1zovGx7J+2ek8GCosfvMLVTiWseWUNDgk/0ws2mlBH5vm6YwKJwmpFaAict4jXSw
IQI6ceP8uvo+khF/UlHoPCOSWGIiwJuvamZ+3ZByMx/luedcg/cjRvYQppL4N19z
Rqlt/tQBctLN8ovNmUwvonH0D5+dlRHfzkxQnMKuQz+QCAwx9QaYPbXi8Y9QNWaU
6pdIxVkPZjzv7nIpCPJOwhZalVzuwgZrbDlC/36BZkSEMZfCBkHZs2VDmcg+XyUu
Nsxr/Q0iRt0Eg4Riie6NUlUpqBAkX4ZenmDy4lVKXaXyR6RzFx8Iv0x/EDDqWcea
yfzT3GIJ3sGihaRdolBSw4+MP5FmvY5TBk3wPrPhplGr+x1QfyQgq45SdYslXoi8
PlCRpnUcwEICjtxrV5hf2kWSRRual17ECjqQ/XfQ3hRz48zaqzg=
=BEyh
—–END PGP SIGNATURE—–


