Impersonation Vulnerability in Veeam Service Provider Console
CVE-2026-58073

9.5CRITICAL

Key Information:

Vendor

Veeam

Vendor
CVE Published:
4 August 2026

What is CVE-2026-58073?

A vulnerability in the Veeam Service Provider Console allows unauthenticated attackers to impersonate a managed agent, enabling them to retrieve sensitive credentials associated with that agent. This flaw poses significant security risks, as it can lead to unauthorized access and potential exploitation of the affected systems. Proper security measures must be implemented to mitigate the risk associated with this vulnerability.

Affected Version(s)

Service Provider Console 0 < 9.3

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.