Executive brief
Veeam Service Provider Console is a multi-tenant management platform that allows service providers to administer backup and disaster recovery for multiple customers. An unauthenticated attacker can briefly access the proxied appliance API with Portal Administrator privileges during the window immediately after an admin session starts, potentially allowing unauthorized configuration changes or data exposure. This vulnerability requires precise timing but poses a significant risk to service provider operations and customer data protection.
Technical details
CVE-2026-58071 is a session/authentication timing vulnerability in Veeam Service Provider Console versions 9.2.1.33875 and earlier that allows an unauthenticated attacker to access the proxied appliance API with Portal Administrator privileges. The vulnerability exists in a narrow window after an administrator session begins, suggesting a race condition or improper state transition in session initialization. The attack is network-reachable and requires no authentication or user interaction, though it does have an attack complexity modifier (timing). An attacker who successfully exploits this window can perform administrative operations on the console. The vulnerability is fixed in Veeam Service Provider Console 9.3.0.35057 and later.
Affected products
- Veeam Service Provider Console 9.2.1.33875 and earlier 9.x builds
Timeline
- 2026-08-04: disclosed: Published by Veeam and NVD
- 2026-08-04: patched: Fixed in Veeam Service Provider Console 9.3.0.35057