Executive brief
A vulnerability in the Veeam Service Provider Console, a platform used by managed service providers to manage backup and recovery operations, could allow an attacker to execute malicious commands remotely. If exploited, an attacker could gain full control over the management server, potentially compromising customer backup data and disrupting service operations. The issue is specifically related to how the system handles automated scripts within its alarm notification system.
Technical details
A remote code execution vulnerability exists in Veeam Service Provider Console due to improper handling of parameters (CWE-233) within the alarm management component. An attacker with low-privileged network access can exploit this flaw to execute arbitrary code on the server. The vulnerability is specifically tied to the 'AlarmManagement_ScriptExecutionEnabled' feature, which is disabled by default in version 9.2 but may be active if legacy alarms with script actions exist. Attackers can achieve full system compromise (High Confidentiality, Integrity, and Availability impact). The issue is resolved in version 9.2.1.33875, and a manual mitigation is available by disabling script execution in the configuration.overrides.json file.
Affected products
- Veeam Service Provider Console 9.2.0.33215 and all earlier version 9 builds
Timeline
- 2026-05-27: patched: Vulnerability resolved in build 9.2.1.33875
- 2026-05-28: disclosed: Initial NVD publication and advisory release