Junglewise Threat Intelligence

CVE-2026-58072: Veeam Service Provider Console arbitrary file write and RCE

CVE-2026-58072 · Severity: info · CVSS 9 · Published 2026-08-04

Technologies: Veeam Service Provider Console. Vendors: Veeam.

Executive brief

Veeam Service Provider Console is a management platform used by service providers to oversee backup and recovery infrastructure. This vulnerability allows an authenticated attacker to write arbitrary files to the management server, potentially enabling remote code execution and complete system compromise. Organizations using affected versions should upgrade immediately to patch this critical flaw.

Technical details

This vulnerability in Veeam Service Provider Console allows an authenticated attacker to write arbitrary files to the management server, leading to remote code execution. The vulnerability affects Veeam Service Provider Console version 9.2.1.33875 and all earlier version 9 builds. The attack requires valid authentication credentials (PR:L) but can be exploited over the network with low attack complexity. Successful exploitation grants an attacker high-level impact across confidentiality, integrity, and availability of the management server and potentially the entire managed infrastructure. The vulnerability was patched in version 9.3.0.35057 and later.

Affected products

  • Veeam Service Provider Console 9.2.1.33875 and earlier 9.x builds

Timeline

  • 2026-08-04: disclosed
  • 2026-08-04: patched: Fixed in Veeam Service Provider Console 9.3.0.35057

References

Related threats