| KB ID: | 4853 |
| Product: | Veeam Service Provider Console | 9 | 9.1 | 9.2 |
| Published: | 2026-05-27 |
| Last Modified: | 2026-05-29 |
A vulnerability in Veeam Service Provider Console allows for remote code execution.
Severity: Critical
CVSS v3.1 Score: 9.4CVSS:AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: Reported by putsi through HackerOne.
This vulnerability was fixed starting with the following build:
This vulnerability can only be exploited when alarm script execution is enabled. Starting in Veeam Service Provider Console 9.2.0.33215, alarm script execution is disabled by default. The default applies to new deployments and to upgrades where no alarms had a script execution action configured; deployments where this setting remained at the default are not affected by this vulnerability.
Note: The mitigation method discussed below cannot be applied to builds older than Veeam Service Provider Console 9.2.0.33215, because the setting AlarmManagement_ScriptExecutionEnabled was introduced in Veeam Service Provider Console 9.2.0.33215. Therefore, all builds prior to 9.2.0.33215 (e.g., 9.1, 9.0, and 8) are affected and must be upgraded to 9.2.1.33875.
To check whether a Veeam Service Provider Console 9.2.0.33215 deployment is affected:
C:\ProgramData\Veeam\Veeam Availability Console\Configuration\Service\configuration.overrides.json
configuration.overrides.json file, identify the value
"AlarmManagement_ScriptExecutionEnabled":
False, then the deployment is not affected.True, the issue can be mitigated prior to applying 9.2.1.33875 by setting the value to False and restarting the Veeam Management Portal Service.If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case.
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case