External risk intelligence

Veeam Service Provider Console Arbitrary File Write Leading to Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-58072

The Veeam Service Provider Console is a management platform designed for service providers to manage multiple client environments. These consoles are frequently deployed as internet-facing portals or edge-accessible management services to facilitate remote oversight of managed infrastructure, making them commonly reachable from the public internet.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability identified in Veeam Service Provider Console. The issue allows for unauthorized file writing on the management server, which could potentially lead to the execution of malicious code. Understanding the nature of this vulnerability is important for assessing potential risks to our management infrastructure.

  • Allows unauthorized file writes.
  • Important for managing service provider environments.
  • Assess relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by writing arbitrary files to the management server if they have partial administrative privileges. This access allows them to write files to critical locations on the server, potentially leading to full system compromise.

  • Requires partial administrative access.
  • Writes arbitrary files to the management server.
  • Leads to arbitrary file write and remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker with limited access to write arbitrary files to the Veeam management server, potentially leading to the execution of malicious code. The conditions for this risk are when the Veeam Service Provider Console is accessible and an attacker can leverage the file write capability.

  • Management server files could be overwritten.
  • Arbitrary file write capability exploited.
  • Remote code execution may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Veeam Service Provider Console, as a management platform, likely falls under the responsibility of infrastructure or platform teams. The initial step should be to locate all instances of this console, assess their internet exposure and business criticality, and identify the accountable owners to prioritize remediation efforts.

  • Identify affected systems and owners.
  • Verify external reachability and impact.
  • Plan remediation with relevant teams.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Veeam Service Provider Console?

The Veeam Service Provider Console is a centralized management platform used by service providers to oversee and administer data protection and backup operations across multiple client environments from a single interface.

What does CVE-2026-58072 mean?

This CVE identifies an arbitrary file write vulnerability, categorized as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). It means the software fails to properly sanitize user inputs, allowing an attacker to place unauthorized files in system locations, which can lead to full remote code execution.

How is this vulnerability triggered?

An attacker must possess partial administrative privileges to trigger the flaw. Simply accessing the console without these specific credentials does not enable the file write capability; the malicious action requires that established level of existing access to manipulate server files.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal notes that these consoles are often deployed as internet-facing portals to facilitate remote management. If your instance is reachable from the public internet, it falls into the 'likely' risk category for external accessibility, increasing the urgency of your assessment.

What are the first steps to address this?

Start by auditing your infrastructure to locate all active instances of the console. Once identified, evaluate the internet accessibility of each server, determine the business impact if compromised, and coordinate with the platform owners to prioritize remediation.

References