CVE-2026-58071: High severity Veeam Veeam Service Provider Console vulnerability
Published Aug 4, 2026
·Updated
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.
Affected Software
1 affected component
Veeam Veeam Service Provider Console
Event History
Aug 4, 2026
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-58071?
CVE-2026-58071 has a severity rating of 8.2, categorizing it as high risk.
2
How do I fix CVE-2026-58071?
To remediate CVE-2026-58071, it is advised to update the Veeam Service Provider Console to the latest version.
3
What type of attack does CVE-2026-58071 allow?
CVE-2026-58071 allows unauthenticated attackers to access the proxied appliance API as a Portal Administrator.
4
What is the impact of CVE-2026-58071?
The impact of CVE-2026-58071 is that an attacker could exploit the vulnerability to gain elevated access privileges.
5
When was CVE-2026-58071 published?
CVE-2026-58071 was published on August 4, 2026.