Junglewise Threat Intelligence

CVE-2026-64635: Veeam Service Provider Console account takeover via password reset hijacking

CVE-2026-64635 · Severity: medium · CVSS 5.3 · Published 2026-07-30

Technologies: Veeam Service Provider Console. Vendors: Veeam.

Executive brief

A vulnerability in the Veeam Service Provider Console, a tool used by service providers to manage backup services, could allow an attacker to take over user accounts. By manipulating the password reset process, an attacker can trick the system into sending a reset link that directs the user's secret credentials to the attacker instead of the legitimate site. If a user clicks this malicious link in their email, the attacker can gain full access to their account.

Technical details

A Weak Password Recovery Mechanism (CWE-640) exists in the Veeam Service Provider Console due to improper validation of the 'returnUrl' parameter. An unauthenticated remote attacker can craft a password reset request that specifies an attacker-controlled domain in the 'returnUrl' field. When the targeted user receives the legitimate password reset email and clicks the link, the embedded reset token is transmitted to the attacker's server via the Referer header or direct redirection. This allows the attacker to capture the token and complete the password reset process to hijack the account. The vulnerability is resolved in version 9.2.1.33875.

Affected products

  • Veeam Service Provider Console 9.2.1.33875 and earlier

Timeline

  • 2026-05-27: disclosed: Initial KB publication
  • 2026-07-28: patched: KB updated with fix information
  • 2026-07-30: advisory: NVD publication date

References

Related threats