Improper Handling of Return URL in Veeam Service Provider Console
CVE-2026-64635
5.3MEDIUM
What is CVE-2026-64635?
The Veeam Service Provider Console has a vulnerability in its Forgot Password function due to improper handling of the returnUrl parameter. This flaw enables an unauthenticated attacker to manipulate the domain of the generated password reset link. When the victim receives the email and clicks on the link, the reset code is sent to an attacker-controlled site. Consequently, this allows the attacker to compromise the user's account, posing a significant security risk.
Affected Version(s)
Service Provider Console 0 <= 9.2