Description
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.
Published: 2026-08-04
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Veeam Service Provider Console permits an attacker who is not authenticated to reach the proxied appliance API with administrator rights for a very small time window that exists immediately after a legitimate administrator logs in. This allows the attacker to answer API calls as a Portal Administrator without performing any credential-based authentication. The vulnerability is an instance of Improper Authentication (CWE‑306).

Affected Systems

The affected product is Veeam Service Provider Console. No specific version information was provided; the issue applies to all releases of this console that are vulnerable.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The exploit requires timing, as the attacker must act during a brief window after an administrator session begins. The likely attack vector is via network access to the proxied appliance API endpoint, potentially from an external source if that endpoint is exposed. Once exploited, the attacker gains full administrative privileges to the appliance through the API, enabling wide-ranging destructive or exfiltration capabilities.

Generated by OpenCVE AI on August 4, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Veeam Service Provider Console update that removes the authentication bypass
  • Restrict external network access to the proxied appliance API by configuring firewall rules or network segmentation to limit who can reach it
  • Enforce authentication and proper authorization checks on all privileged API endpoints to ensure only legitimate users can execute administrative actions

Generated by OpenCVE AI on August 4, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated privileged API access after admin session starts

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam service Provider Console
Vendors & Products Veeam
Veeam service Provider Console

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Veeam Service Provider Console
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-08-04T17:20:39.237Z

Reserved: 2026-06-28T15:00:00.720Z

Link: CVE-2026-58071

cve-icon Vulnrichment

Updated: 2026-08-04T17:20:33.119Z

cve-icon NVD

Status : Received

Published: 2026-08-04T17:16:56.463

Modified: 2026-08-04T18:16:53.723

Link: CVE-2026-58071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:15:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function