CRITICAL🇵🇱 Wersja polska

CVE-2026-32998

CVSS 9.4v4.0pub. 2026-05-28upd. 2026-05-29

This vulnerability in Veeam Service Provider Console allows for remote code execution.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-233 (Improper Handling of Parameters) allows an attacker to execute arbitrary code remotely on the vulnerable system. Network attack vector (AV:N) without requiring user interaction (UI:N) with low privilege requirements (PR:L) means that basic access to the console is sufficient to conduct a successful attack. The vulnerability affects both resources of the target system and related systems (SC:H/SI:H/SA:H).

Impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code remotely, which can lead to complete system takeover, data theft, and compromise of integrity and availability of both the target system and related systems.

Mitigation & patch

Patches available from the vendor should be applied in accordance with references published at https://www.veeam.com/kb4853. Until patches are deployed, it is recommended to restrict network access to Veeam Service Provider Console exclusively to trusted hosts and monitor logs for unauthorized activities.

Who is affected

Veeam Service Provider Console — versions indicated in vendor references (https://www.veeam.com/kb4853)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References