CVE-2026-64635 | Veeam Service Provider Console up to 9.2 Forgot Password returnUrl password recovery
A vulnerability, which was classified as critical, has been found in Veeam Service Provider Console up to 9.2. This affects an unknown function of the component Forgot Password. The manipulation of the argument returnUrl leads to weak password recovery.
This vulnerability is listed as CVE-2026-64635. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More