Arbitrary File Write in Veeam Service Provider Console Leading to Remote Code Execution
CVE-2026-58072

9CRITICAL

Key Information:

Vendor

Veeam

Vendor
CVE Published:
4 August 2026

What is CVE-2026-58072?

A flaw in the Veeam Service Provider Console enables an attacker to perform arbitrary file writes on the management server. This can result in unauthorized remote code execution, posing significant security threats to systems that utilize this software.

Affected Version(s)

Service Provider Console 0 < 9.3

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.