Junglewise Threat Intelligence

CVE-2026-58071: Veeam Service Provider Console unauthenticated admin API access

CVE-2026-58071 · Severity: info · CVSS 8.2 · Published 2026-08-04

Technologies: Veeam Service Provider Console. Vendors: Veeam.

Executive brief

Veeam Service Provider Console is a multi-tenant management platform that allows service providers to administer backup and disaster recovery for multiple customers. An unauthenticated attacker can briefly access the proxied appliance API with Portal Administrator privileges during the window immediately after an admin session starts, potentially allowing unauthorized configuration changes or data exposure. This vulnerability requires precise timing but poses a significant risk to service provider operations and customer data protection.

Technical details

CVE-2026-58071 is a session/authentication timing vulnerability in Veeam Service Provider Console versions 9.2.1.33875 and earlier that allows an unauthenticated attacker to access the proxied appliance API with Portal Administrator privileges. The vulnerability exists in a narrow window after an administrator session begins, suggesting a race condition or improper state transition in session initialization. The attack is network-reachable and requires no authentication or user interaction, though it does have an attack complexity modifier (timing). An attacker who successfully exploits this window can perform administrative operations on the console. The vulnerability is fixed in Veeam Service Provider Console 9.3.0.35057 and later.

Affected products

  • Veeam Service Provider Console 9.2.1.33875 and earlier 9.x builds

Timeline

  • 2026-08-04: disclosed: Published by Veeam and NVD
  • 2026-08-04: patched: Fixed in Veeam Service Provider Console 9.3.0.35057

References

Related threats