A GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console
bishopfox.com | vulnerability | Critical | #rce | #backup-security | #authentication | #vulnerability | #cve | #security-research | #veeam | #cve-2026-58073 | #cve-2026-58072
Summary
Bishop Fox proves unauthenticated RCE in Veeam Service Provider Console by chaining CVE-2026-58073 (CVSS 9.5, agent impersonation) with CVE-2026-58072 (CVSS 9.0, arbitrary file write); patch to 9.3.0 and check logs with the provided safe detection tool, which also covers two sibling CVEs.
Why it matters
This critical vulnerability chain allows unauthenticated take-over of backup control planes across multi-tenant deployments.
- Vendor
- Veeam
- Product
- Veeam Service Provider Console
- Affected versions
- before 9.3.0
- CVSS
- 9.8
- Published
- Collected
Skip to content