Junglewise Threat Intelligence

CVE-2026-41723: VMware Cloud Foundation Operations stored XSS in policies and widgets

CVE-2026-41723 · Severity: high · CVSS 8 · Published 2026-06-08

Executive brief

VMware Cloud Foundation Operations, a platform used for managing and monitoring hybrid cloud infrastructure, is affected by security vulnerabilities that allow malicious scripts to be saved within the system. An attacker with basic user permissions could use these scripts to trick administrators into performing unauthorized actions. This could lead to a full takeover of the management console, potentially disrupting cloud operations or exposing sensitive configuration data.

Technical details

VMware Cloud Foundation Operations (formerly Aria Operations) contains multiple stored cross-site scripting (XSS) vulnerabilities. The flaw exists because the application fails to properly sanitize user-supplied input when creating policies, views, or text-widgets. An authenticated attacker with low-level privileges can inject malicious JavaScript that executes in the context of other users, including administrators, when they view the affected components. Successful exploitation requires a victim to interact with the malicious content and can result in the attacker performing administrative actions or hijacking sessions. Patches are available in versions 9.1.0.0, 9.0.2.0 EP2, and 8.18.7 depending on the specific product line.

Affected products

  • VMware Cloud Foundation Operations 9.1.x.x, 9.0.x.x
  • VMware Aria Operations 8.x, 5.x
  • VMware vSphere Foundation 9.1.x.x, 9.0.x.x
  • VMware Telco Cloud Platform 5.x

Timeline

  • 2026-06-08: disclosed: Initial advisory publication by Broadcom/VMware
  • 2026-06-08: patched: Fixed versions released across multiple product lines

References

Related threats