CVE-2026-64635: Medium severity Veeam Veeam Service Provider Console vulnerability
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64635?
CVE-2026-64635 has a medium severity rating of 5.3.
How do I fix CVE-2026-64635?
To fix CVE-2026-64635, ensure that the returnUrl parameter is properly validated to prevent unauthorized control of password reset links.
What is the risk associated with CVE-2026-64635?
CVE-2026-64635 has a risk score of 31, indicating a significant security concern due to its exploitation potential.
Who is affected by CVE-2026-64635?
CVE-2026-64635 affects users of the Veeam Service Provider Console who utilize the Forgot Password function.
What type of attack can exploit CVE-2026-64635?
CVE-2026-64635 allows unauthenticated attackers to exploit the Forgot Password function by manipulating the returnUrl parameter.