Impersonation Vulnerability in Veeam Service Provider Console
CVE-2026-58073

9.5CRITICAL

Key Information:

Vendor

Veeam

Vendor
CVE Published:
4 August 2026

What is CVE-2026-58073?

CVE-2026-58073 is a vulnerability found in the Veeam Service Provider Console, a platform designed for managing and monitoring virtual machine backups and data recovery operations. This vulnerability allows an unauthenticated attacker to impersonate a managed agent, exploiting the trust relationship between agents and the console. By doing so, the attacker can obtain sensitive credentials associated with that agent, which can lead to unauthorized access to other resources managed by Veeam. The implications of this vulnerability are particularly severe for organizations relying on Veeam for critical data protection and recovery, as an attacker gaining these credentials could disrupt operations, access sensitive data, or manipulate backup processes.

Potential impact of CVE-2026-58073

  1. Unauthorized Access to Credentials: The ability to impersonate a managed agent means that an attacker could gain access to sensitive credentials, potentially allowing them to execute further attacks within the organization’s environment.

  2. Operational Disruption: By obtaining control over backup and recovery processes, an attacker could sabotage data integrity or availability, leading to critical operational downtime that could impact business continuity.

  3. Increased Risk of Data Breach: With access to management credentials, an attacker could exfiltrate sensitive data, resulting in data breaches that may have legal and financial repercussions for the organization, as well as damage to its reputation.

Affected Version(s)

Service Provider Console 0 < 9.3

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.