← All Advisories

A stored XSS spanning VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts

Status: UPDATED  |  Advisory ID: CVE-2026-41723

Key Details

CVECVE-2026-41723
CVSS Score / Version8.0 (High) / CVSS v3.1
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsVMware aria_operations, VMware cloud_foundation, VMware telco_cloud_platform, and VMware vsphere
Classified asCWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))
Exploitation prediction (EPSS)0.40% probability of exploitation in the next 30 days (34% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
VMwarearia_operations
VMwarecloud_foundation
VMwaretelco_cloud_platform
VMwarevsphere
SubsystemsGeneral OT
SectorsMultiple

What to Know

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

What to Do

Monitor VMware's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-41723