Junglewise Threat Intelligence

CVE-2026-41722: VMware Cloud Foundation Operations multiple stored XSS

CVE-2026-41722 · Severity: high · CVSS 8 · Published 2026-06-08

Executive brief

VMware Cloud Foundation Operations, a platform used for managing and monitoring hybrid cloud environments, is affected by multiple security flaws. A malicious user with basic permissions to create dashboard elements like policies or text widgets can inject malicious scripts into the system. If an administrator views these elements, the attacker could potentially perform unauthorized administrative actions, leading to a full takeover of the management console.

Technical details

VMware Cloud Foundation Operations (formerly Aria Operations) contains multiple stored cross-site scripting (XSS) vulnerabilities. The root cause is improper sanitization of user-supplied input within the components responsible for creating policies, views, or text-widgets. An attacker with low-privileged access (PR:L) can inject malicious JavaScript that executes in the context of other users, including administrators, when they interact with the affected UI elements (UI:R). Successful exploitation allows the attacker to perform administrative actions, potentially leading to full compromise of the application. Patches have been released for affected versions including 9.1.0.0, 9.0.2.0 EP2, and 8.18.7.

Affected products

  • VMware Cloud Foundation Operations 9.1.x.x, 9.0.x.x
  • VMware Aria Operations 8.x, 5.x
  • VMware Cloud Foundation 9.1.x.x, 9.0.x.x, 5.x
  • VMware vSphere Foundation 9.1.x.x, 9.0.x.x
  • VMware Telco Cloud Platform 5.x

Timeline

  • 2026-06-08: disclosed: Initial advisory publication by Broadcom/VMware
  • 2026-06-08: patched: Patches made available across multiple product lines

References

Related threats