Junglewise Threat Intelligence

CVE-2026-58073: Veeam Service Provider Console agent impersonation

CVE-2026-58073 · Severity: info · CVSS 9.5 · Published 2026-08-04

Technologies: Veeam Service Provider Console. Vendors: Veeam.

Executive brief

Veeam Service Provider Console is a management platform used by service providers to administer and monitor backup and disaster recovery systems across customer environments. An unauthenticated attacker can impersonate a managed agent and steal its credentials, potentially gaining unauthorized access to critical backup and recovery infrastructure without authentication or legitimate access rights.

Technical details

This is an authentication bypass vulnerability in Veeam Service Provider Console that allows an unauthenticated attacker to impersonate a managed agent over the network. The vulnerability requires some attack complexity (AC:H) but no user interaction or privileges. By exploiting this flaw, an attacker can obtain agent credentials, which compromises confidentiality and integrity of protected systems. The vulnerability affects versions 9.2.1.33875 and all earlier 9.x builds and is fixed in version 9.3.0.35057.

Affected products

  • Veeam Service Provider Console 9.2.1.33875 and earlier 9.x builds

Timeline

  • 2026-08-04: disclosed

References

Related threats