VDB

GCVE-110-NCSC-2026-276

GCVE-110-NCSC-2026-276
Advisory Published
Vulnetix · Advisory published August 5, 2026
A vulnerability in Veeam Service Provider Console enables an unauthenticated attacker to impersonate a managed agent and acquire that agent's credentials.

Weaknesses (CWE)

CWE-288Authentication Bypass Using an Alternate Path or ChannelCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-789Memory Allocation with Excessive Size ValueCWE-306Missing Authentication for Critical Function

Affected Products

VendorProductVersionsPlatforms
Veeamvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›