MEDIUMVulnerability

CVE-2026-64635

Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.

Properties

severity
MEDIUM
score
5.3
epss_score
0.0019
cve_id
CVE-2026-64635
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
published_at
2026-07-30T06:25:59.930
last_modified
2026-09-03T17:02:54.670
epss_percentile
0.08737

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Weak Password Recovery Mechanism for Forgotten Password

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-64635 — Ninja Signal Threat Intelligence | Ninja Signal