Description
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.
Published: 2026-07-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves improper validation of the returnUrl parameter in the Forgot Password feature of Veeam Service Provider Console. An unauthenticated attacker can supply a malicious domain within this parameter, causing the generated password reset link to point to an attacker‑controlled host. When the legitimate user follows the email link, the reset code is sent to the attacker, enabling account takeover by the attacker without any additional authentication steps. This flaw directly impacts confidentiality, integrity, and availability of user accounts and is identified as CWE‑640.

Affected Systems

Veeam Service Provider Console is the sole affected product listed by the CNA. The specific versions impacted are not enumerated in the available data, so all releases of the console remain potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% shows a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through an email response mechanism where the user is tricked into clicking a reset link. An attacker can therefore exploit this weakness with little effort and no presence on the target network, assuming the reset link is delivered via standard email.

Generated by OpenCVE AI on August 3, 2026 at 11:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Veeam Service Provider Console to the latest version providing a fixed returnUrl validation
  • Configure the console to restrict or whitelist allowed returnUrl domains to prevent external domain redirection
  • Implement monitoring of password reset email traffic for unexpected domains to detect potential abuse

Generated by OpenCVE AI on August 3, 2026 at 11:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 03 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Return URL Manipulation in Veeam Service Provider Console Enables Password Reset Token Theft

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam service Provider Console
Vendors & Products Veeam
Veeam service Provider Console

Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Veeam Service Provider Console
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-30T12:44:36.592Z

Reserved: 2026-07-20T15:00:00.696Z

Link: CVE-2026-64635

cve-icon Vulnrichment

Updated: 2026-07-30T12:43:41.415Z

cve-icon NVD

Status : Received

Published: 2026-07-30T06:25:59.930

Modified: 2026-07-30T13:16:54.110

Link: CVE-2026-64635

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:04Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password