Executive brief
VMware ESX, a platform used to run multiple virtual servers on a single physical machine, contains a flaw that prevents certain administrative actions from being recorded in system logs. A malicious user who already has high-level administrative access could use this to perform unauthorized operations without leaving an audit trail. While this does not grant new access, it significantly hinders the ability of security teams to detect or investigate internal misconduct or compromised admin accounts.
Technical details
VMware ESX is affected by an insufficient logging vulnerability (CWE-778). The flaw allows a malicious actor with high-level administrative privileges (PR:H) to execute specific operations that fail to trigger expected audit logs. The attack vector is listed as network-based, though it requires pre-existing administrative credentials. This vulnerability impacts the integrity of the audit trail rather than the direct confidentiality or availability of the host. Patches have been released for ESXi 8.0, 9.0, and 9.1 branches, as well as associated VMware Foundation and Cloud products.
Affected products
- VMware ESX / ESXi 8.0 before ESXi80U3j-25429389, 9.0.x.x before ESXi-9.0.2.0100-25595025, 9.1.x.x before ESXi-9.1.0.0-25370933
- VMware Cloud Foundation 5.x before 5.2.4, 9.0.x.x, 9.1.x.x
- VMware vSphere Foundation 9.0.x.x, 9.1.x.x
- VMware Telco Cloud Platform 5.0.x, 5.1.x
Timeline
- 2026-07-29: advisory: Initial VMSA-2026-0006 advisory published by Broadcom
- 2026-07-30: disclosed: NVD publication date