Improper Handling of Return URL in Veeam Service Provider Console
CVE-2026-64635

5.3MEDIUM

Key Information:

Vendor

Veeam

Vendor
CVE Published:
30 July 2026

What is CVE-2026-64635?

The Veeam Service Provider Console has a vulnerability in its Forgot Password function due to improper handling of the returnUrl parameter. This flaw enables an unauthenticated attacker to manipulate the domain of the generated password reset link. When the victim receives the email and clicks on the link, the reset code is sent to an attacker-controlled site. Consequently, this allows the attacker to compromise the user's account, posing a significant security risk.

Affected Version(s)

Service Provider Console 0 <= 9.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.