← All Advisories

Stored XSS in VMware Cloud Foundation Operations lets privileged users trigger admin actions via injected scripts

Status: UPDATED  |  Advisory ID: CVE-2026-41724

Key Details

CVECVE-2026-41724
CVSS Score / Version8.0 (High) / CVSS v3.1
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsVMware aria_operations, VMware cloud_foundation, and VMware telco_cloud_platform
Classified asCWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))
Exploitation prediction (EPSS)0.31% probability of exploitation in the next 30 days (24% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
VMwarearia_operations
VMwarecloud_foundation
VMwaretelco_cloud_platform
SubsystemsGeneral OT
SectorsMultiple

What to Know

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

What to Do

Monitor VMware's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-41724