CVE-2026-64635
MEDIUMVeeam Service Provider Console < 9.2 - Weak Password Recovery Mechanism for Forgotten Password
Title source: ruleDescription
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.
References (1)
Core 1
Core References
Scores
CVSS v3
5.3
EPSS
0.0019
EPSS Percentile
9.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-640
Status
published
Products (1)
Veeam/Service Provider Console
< 9.2
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026