Executive brief
Veeam Service Provider Console is a management platform used by service providers to oversee backup and recovery infrastructure. This vulnerability allows an authenticated attacker to write arbitrary files to the management server, potentially enabling remote code execution and complete system compromise. Organizations using affected versions should upgrade immediately to patch this critical flaw.
Technical details
This vulnerability in Veeam Service Provider Console allows an authenticated attacker to write arbitrary files to the management server, leading to remote code execution. The vulnerability affects Veeam Service Provider Console version 9.2.1.33875 and all earlier version 9 builds. The attack requires valid authentication credentials (PR:L) but can be exploited over the network with low attack complexity. Successful exploitation grants an attacker high-level impact across confidentiality, integrity, and availability of the management server and potentially the entire managed infrastructure. The vulnerability was patched in version 9.3.0.35057 and later.
Affected products
- Veeam Service Provider Console 9.2.1.33875 and earlier 9.x builds
Timeline
- 2026-08-04: disclosed
- 2026-08-04: patched: Fixed in Veeam Service Provider Console 9.3.0.35057