CVE-2026-58067
Received Received - Intake

Memory Exhaustion DoS in Veeam Service Provider Console

Vulnerability report for CVE-2026-58067, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: HackerOne

Description

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
veeam service_provider_console *
veeam service_provider_console to 9.3.0.35057 (exc)
veeam service_provider_console 9.3.0.35057

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-58067 is a high-severity vulnerability in Veeam Service Provider Console versions 9.2.1.33875 and earlier. It allows an unauthenticated attacker to exhaust host memory, causing a denial of service (DoS) condition by consuming excessive system resources.

Detection Guidance

Monitor for unusual memory consumption or service crashes in Veeam Service Provider Console. Check logs for repeated failed connection attempts or resource exhaustion alerts. Use system monitoring tools like top, htop, or Windows Resource Monitor to track memory usage by the Veeam service.

Impact Analysis

This vulnerability could allow attackers to disrupt services by consuming too much memory, leading to system crashes or slowdowns. It affects Veeam Service Provider Console versions before 9.3.0.35057.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing service disruptions through denial of service. GDPR requires maintaining data availability, and HIPAA mandates reliable access to protected health information. A DoS condition may violate these requirements by preventing authorized access to systems handling sensitive data.

Mitigation Strategies

Upgrade Veeam Service Provider Console to version 9.3.0.35057 or later immediately. If upgrading is not possible, restrict network access to the console and monitor for suspicious activity. Apply network segmentation to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58067. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart