CVE-2026-41723 PUBLISHED

VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)

Assigner: vmware
Reserved: 22.04.2026 Published: 08.06.2026 Updated: 08.06.2026

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 8

Product Status

Vendor VMware
Product VCF operations
Versions Default: affected
  • affected from 9.1.x.x to 9.1.0.0 (incl.)
  • affected from 9.0.x.x to 9.0.2.0 EP2 (incl.)
  • affected from 5.x to 8.18.7 (incl.)
Vendor VMware
Product VMware Aria Operations
Versions Default: affected
  • affected from 8.18.x to 8.18.6 (incl.)
  • affected from 8.18.x to 8.18.7 (incl.)
Vendor VMware
Product VMware Telco Cloud Platform
Versions Default: affected
  • affected from 5.x to 8.18.7 (incl.)

References