CVE-2026-41724 PUBLISHED

VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)

Assigner: vmware
Reserved: 22.04.2026 Published: 08.06.2026 Updated: 08.06.2026

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 8

Product Status

Vendor VMware
Product VCF operations
Versions Default: affected
  • affected from 5.x to 8.18.7 (incl.)
Vendor VMware
Product VMware Aria Operations
Versions Default: affected
  • affected from 8.18.x to 8.18.7 (incl.)
Vendor VMware
Product VMware Telco Cloud Platform
Versions Default: affected
  • affected from 5.x to 8.18.7 (incl.)

References