← Back to CVE List
CVE-2026-41722NVD
Vulnerability Summary
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
CVSS v3.1 Base Metrics — Score 8.0 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Vmware Aria Operations >= 8.0 and < 8.18.7
- Vmware Cloud Foundation >= 5.0 and < 8.18.7
- Vmware Cloud Foundation >= 9.0 and < 9.0.2.0
- Vmware Cloud Foundation
- Vmware Telco Cloud Platform >= 5.0 and <= 5.1
- Vmware Vsphere >= 9.0 and < 9.0.2.0
- Vmware Vsphere
- Vmware Aria Operations 8.18.7
- Vmware Cloud Foundation 8.18.7
- Vmware Cloud Foundation 9.0.2.0
- Vmware Vsphere 9.0.2.0