← Back to CVE List
CVE-2026-41724NVD
Vulnerability Summary
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
CVSS v3.1 Base Metrics — Score 8.0 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Vmware Aria Operations >= 8.0 and < 8.18.7
- Vmware Cloud Foundation >= 5.0 and < 8.18.7
- Vmware Telco Cloud Platform >= 5.0 and < 8.18.7
- Vmware Aria Operations 8.18.7
- Vmware Cloud Foundation 8.18.7
- Vmware Telco Cloud Platform 8.18.7