Description
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.
Published: 2026-08-04
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Veeam Service Provider Console allows an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. This flaw, classified as CWE‑288 (Authentication Bypass), can result in an attacker being able to masquerade as a legitimate agent and gain access to sensitive credentials that may be used to control other components of the managed infrastructure. The compromised credentials can enable further lateral movement, data exfiltration, or administrative takeover of the target environment.

Affected Systems

The affected system is the Veeam Service Provider Console. No specific version information was provided, so all installations of the console are potentially vulnerable. Administrators should verify the product version and consult Veeam documentation for any additional guidance.

Risk and Exploitability

The CVSS score of 9.5 indicates a high severity vulnerability, with the EPSS score unavailable and the vulnerability not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated network connection to the console, as described in the advisory. If an attacker can reach the console, they can exploit the authentication bypass to impersonate an agent and obtain credentials, which could lead to full control of the managed environment. The risk is high, and the vulnerability is actively exploitable under the conditions described.

Generated by OpenCVE AI on August 4, 2026 at 19:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Veeam patch or hotfix for the Service Provider Console
  • Restrict external network access to the Service Provider Console to trusted IP ranges or VPN tunnels
  • Enable and monitor logging for unauthorized login attempts or suspicious authentication activity
  • Consider implementing multi‑factor authentication for console access to reduce the impact of credential compromise

Generated by OpenCVE AI on August 4, 2026 at 19:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Impersonation in Veeam Service Provider Console Exposes Agent Credentials

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam service Provider Console
Vendors & Products Veeam
Veeam service Provider Console

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Veeam Service Provider Console
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-08-05T03:57:08.825Z

Reserved: 2026-06-28T15:00:00.720Z

Link: CVE-2026-58073

cve-icon Vulnrichment

Updated: 2026-08-04T17:19:17.289Z

cve-icon NVD

Status : Received

Published: 2026-08-04T17:16:56.930

Modified: 2026-08-05T05:17:02.413

Link: CVE-2026-58073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:45:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel