Impersonation Vulnerability in Veeam Service Provider Console
CVE-2026-58073
What is CVE-2026-58073?
CVE-2026-58073 is a vulnerability found in the Veeam Service Provider Console, a platform designed for managing and monitoring virtual machine backups and data recovery operations. This vulnerability allows an unauthenticated attacker to impersonate a managed agent, exploiting the trust relationship between agents and the console. By doing so, the attacker can obtain sensitive credentials associated with that agent, which can lead to unauthorized access to other resources managed by Veeam. The implications of this vulnerability are particularly severe for organizations relying on Veeam for critical data protection and recovery, as an attacker gaining these credentials could disrupt operations, access sensitive data, or manipulate backup processes.
Potential impact of CVE-2026-58073
-
Unauthorized Access to Credentials: The ability to impersonate a managed agent means that an attacker could gain access to sensitive credentials, potentially allowing them to execute further attacks within the organization’s environment.
-
Operational Disruption: By obtaining control over backup and recovery processes, an attacker could sabotage data integrity or availability, leading to critical operational downtime that could impact business continuity.
-
Increased Risk of Data Breach: With access to management credentials, an attacker could exfiltrate sensitive data, resulting in data breaches that may have legal and financial repercussions for the organization, as well as damage to its reputation.
Affected Version(s)
Service Provider Console 0 < 9.3