Description
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.
Published: 2026-08-04
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Veeam Service Provider Console permits an unauthenticated user to intentionally exhaust host memory, ultimately stopping legitimate services from running. The weakness is a classic instance of CWE‑789, where insufficient resource checks allow service degradation for all users of the affected host.

Affected Systems

The vulnerability affects the Veeam Service Provider Console. No specific versions were disclosed, so the entire product line should be considered potentially vulnerable until a patch is found.

Risk and Exploitability

The remote attacker can trigger the memory exhaustion without needing credentials, resulting in a high‑impact denial of service with a CVSS score of 8.7. EPSS is not provided, and the vulnerability is not listed in the CISA KEV catalog, but the lack of mitigation guidance makes it a high priority for patching.

Generated by OpenCVE AI on August 4, 2026 at 19:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update for Veeam Service Provider Console as described in Veeam KB4893.
  • Restrict network access to the console by enforcing firewall rules or limiting the exposure to trusted networks.
  • Implement host‑level memory monitoring and alerts to detect and respond to abnormal memory consumption early.

Generated by OpenCVE AI on August 4, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Memory Exhaustion Leading to Denial of Service in Veeam Service Provider Console

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam service Provider Console
Vendors & Products Veeam
Veeam service Provider Console

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.
Weaknesses CWE-789
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Veeam Service Provider Console
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-08-04T17:20:55.769Z

Reserved: 2026-06-28T15:00:00.720Z

Link: CVE-2026-58067

cve-icon Vulnrichment

Updated: 2026-08-04T17:20:48.615Z

cve-icon NVD

Status : Received

Published: 2026-08-04T17:16:56.333

Modified: 2026-08-04T18:16:53.613

Link: CVE-2026-58067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:45:03Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value