PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64635 Veeam CVE debrief

CVE-2026-64635 is a medium-severity vulnerability in Veeam Service Provider Console's Forgot Password function. An unauthenticated attacker can manipulate the returnUrl parameter to control the domain of the generated password reset link. When the targeted user clicks the link, the reset code is transmitted to an attacker-controlled host, potentially allowing account takeover. The vulnerability affects Veeam Service Provider Console deployments and requires review of configurations and monitoring for suspicious activity. Security teams should prioritize patching or mitigation efforts to prevent potential account takeover. Limited detail is available on affected versions and remediation steps, so defenders should verify configurations, monitor for suspicious activity, and review compensating controls. This CVE record was published on 2026-07-30T06:25:59.930Z and has not been modified since then.

Vendor
Veeam
Product
Service Provider Console
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-09-03
Advisory published
2026-07-30
Advisory updated
2026-09-03

Who should care

Security teams responsible for Veeam Service Provider Console deployments should review configurations and monitor for suspicious activity. Penetration testers and red teamers may be interested in testing the vulnerability's exploitability. Affected operators should prioritize patching or mitigation efforts to prevent potential account takeover. Platform administrators should review affected scope and severity to ensure proper defensive measures are in place.

Technical summary

CVE-2026-64635 is a medium-severity vulnerability in Veeam Service Provider Console's Forgot Password function. An unauthenticated attacker can manipulate the returnUrl parameter to control the domain of the generated password reset link. When the targeted user clicks the link, the reset code is transmitted to an attacker-controlled host, potentially allowing account takeover. The vulnerability affects Veeam Service Provider Console deployments and requires review of configurations and monitoring for suspicious activity.

Defensive priority

Medium-priority defensive review recommended due to potential for targeted attacks via password reset link manipulation.

Recommended defensive actions

  • Review Veeam Service Provider Console configuration for potential exposure to CVE-2026-64635
  • Implement compensating controls for password reset processes
  • Monitor for suspicious password reset attempts
  • Inventory affected systems for patching
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Evidence from official CVE and NVD sources indicates improper handling of the returnUrl parameter in Veeam Service Provider Console's Forgot Password function. Limited detail available on affected versions and remediation steps. Defenders should verify configurations, monitor for suspicious activity, and review compensating controls. The CVE record was published on 2026-07-30T06:25:59.930Z and has not been modified since then. Affected systems may require patching or mitigation to prevent potential account takeover.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64635 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64635

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64635 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64635

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.