Junglewise Threat Intelligence

CVE-2026-41724: VMware Cloud Foundation Operations stored XSS in policies and widgets

CVE-2026-41724 · Severity: high · CVSS 8 · Published 2026-06-08

Executive brief

VMware Cloud Foundation Operations, a platform used for managing and monitoring hybrid cloud environments, is affected by multiple security flaws. An attacker with basic user permissions can inject malicious scripts into shared components like policies or dashboards. If an administrator views these components, the attacker could potentially hijack their session to perform unauthorized administrative actions, leading to full system compromise.

Technical details

VMware Cloud Foundation Operations (formerly Aria Operations) contains multiple stored cross-site scripting (XSS) vulnerabilities. The root cause is improper sanitization of user-supplied input within policies, views, and text-widgets. An attacker with low-privileged access (PR:L) can inject malicious JavaScript that executes in the context of other users, including administrators, when they interact with the affected components (UI:R). Successful exploitation allows the attacker to perform administrative actions, potentially leading to a complete compromise of confidentiality, integrity, and availability. Patches are available in versions 9.1.0.0, 9.0.2.0 EP2, and 8.18.7 depending on the specific product deployment.

Affected products

  • VMware Cloud Foundation Operations 9.1.x, 9.0.x, 5.x
  • VMware Aria Operations 8.x, 5.x
  • VMware vSphere Foundation 9.1.x, 9.0.x
  • VMware Telco Cloud Platform 5.x

Timeline

  • 2026-06-08: disclosed: Initial publication of VMSA-2026-0004
  • 2026-06-08: patched

References

Related threats