Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

A GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console

Summary

Bishop Fox proves unauthenticated RCE in Veeam Service Provider Console by chaining CVE-2026-58073 (CVSS 9.5, agent impersonation) with CVE-2026-58072 (CVSS 9.0, arbitrary file write); patch to 9.3.0 and check logs with the provided safe detection tool, which also covers two sibling CVEs.

Why it matters

This critical vulnerability chain allows unauthenticated take-over of backup control planes across multi-tenant deployments.
Vendor
Veeam
Product
Veeam Service Provider Console
Affected versions
before 9.3.0
CVSS
9.8
Published
Collected

original ↗

Related coverage

back