Veeam Service Provider Console VSPC Auth Bypass: Air Gap Agent Impersonation
CVE-2026-58073 Published on August 4, 2026
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.
Weakness Type
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
Affected Versions
Veeam Service Provider Console:- Before 9.3 is affected.