Junglewise Threat Intelligence

CVE-2026-41709: VMware ESX insufficient logging vulnerability

CVE-2026-41709 · Severity: low · CVSS 2.7 · Published 2026-07-30

Executive brief

VMware ESX, a platform used to run multiple virtual servers on a single physical machine, contains a flaw that prevents certain administrative actions from being recorded in system logs. A malicious user who already has high-level administrative access could use this to perform unauthorized operations without leaving an audit trail. While this does not grant new access, it significantly hinders the ability of security teams to detect or investigate internal misconduct or compromised admin accounts.

Technical details

VMware ESX is affected by an insufficient logging vulnerability (CWE-778). The flaw allows a malicious actor with high-level administrative privileges (PR:H) to execute specific operations that fail to trigger expected audit logs. The attack vector is listed as network-based, though it requires pre-existing administrative credentials. This vulnerability impacts the integrity of the audit trail rather than the direct confidentiality or availability of the host. Patches have been released for ESXi 8.0, 9.0, and 9.1 branches, as well as associated VMware Foundation and Cloud products.

Affected products

  • VMware ESX / ESXi 8.0 before ESXi80U3j-25429389, 9.0.x.x before ESXi-9.0.2.0100-25595025, 9.1.x.x before ESXi-9.1.0.0-25370933
  • VMware Cloud Foundation 5.x before 5.2.4, 9.0.x.x, 9.1.x.x
  • VMware vSphere Foundation 9.0.x.x, 9.1.x.x
  • VMware Telco Cloud Platform 5.0.x, 5.1.x

Timeline

  • 2026-07-29: advisory: Initial VMSA-2026-0006 advisory published by Broadcom
  • 2026-07-30: disclosed: NVD publication date

References

Related threats