2026-08-06 · view entry permalink →
Veeam Service Provider Console and Veeam ONE — ten CVEs, headed by an unauthenticated CVSS 10.0 remote code execution on the Veeam ONE agent host
Veeam published two security bulletins on 2026-08-04 covering ten vulnerabilities. CERT-FR carried both products and the full set the following day (CERT-FR, 2026-08-05); NCSC-NL's advisory of the same date covers only Service Provider Console and its four CVEs, and does not mention Veeam ONE or the 10.0 agent-host flaw at all (NCSC-NL, 2026-08-05) — worth knowing if your patch intake is driven by a single national feed. In Veeam ONE, CVE-2026-64633 is described by the vendor as allowing remote unauthenticated code execution on the agent host and is scored CVSS v4.0 10.0 with no privileges and no user interaction required (Veeam, 2026-08-04). Its siblings in the same product are CVE-2026-58075 (8.7), an unauthenticated arbitrary file read from the host that the vendor says can be leveraged to escalate privileges locally; CVE-2026-58074 (8.6), arbitrary code execution on the server by a high-privileged user; CVE-2026-64631 (8.6), SQL injection by a low-privileged user extracting database contents; CVE-2026-64634 (8.4), local privilege escalation into the Reporter service context; and CVE-2026-64630 (5.3), retrieval of report data outside a shared link's scope (Veeam, 2026-08-04). All affect Veeam ONE 13.0.2.6723 and all earlier version 13 builds, and all are resolved in 13.1.0.7034 (Veeam, 2026-08-04).
In Veeam Service Provider Console, CVE-2026-58073 (CVSS v4.0 9.5) allows an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials — though the vendor's own vector records high attack complexity, which is the one meaningful brake on the four (Veeam, 2026-08-04). CVE-2026-58072 (9.0) permits arbitrary file write on the management server leading to remote code execution; CVE-2026-58067 (8.7) lets an unauthenticated attacker exhaust host memory for denial of service; and CVE-2026-58071 (8.2) allows an unauthenticated attacker to reach the proxied appliance API as Portal Administrator during a short window after an administrator session begins (Veeam, 2026-08-04). These affect Service Provider Console 9.2.1.33875 and all earlier version 9 builds, resolved in 9.3.0.35057 (Veeam, 2026-08-04).
No party — vendor or CERT — reports exploitation of any of the ten. The reason this still warrants attention ahead of the ordinary patch cycle is what the two products are: Service Provider Console is the multi-tenant management plane through which service providers administer customer backup estates, and Veeam ONE is the monitoring platform over that same estate. An agent-credential impersonation flaw on the former and an unauthenticated code-execution flaw on the latter both land on infrastructure that holds broad, standing access into the systems an organisation would rely on to recover — and backup infrastructure is a recognised pre-encryption target rather than a bystander.
A vulnerability allowing remote unauthenticated code execution on the agent host.
impersonate a managed agent and obtain that agent's credentials