CVE-2026-64635

MEDIUM

Veeam Service Provider Console < 9.2 - Weak Password Recovery Mechanism for Forgotten Password

Title source: rule
STIX 2.1

Description

Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 9.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-640
Status published
Products (1)
Veeam/Service Provider Console < 9.2
Published Jul 30, 2026
Tracked Since Jul 30, 2026