Executive brief
VMware Cloud Foundation Operations, a platform used for managing and monitoring hybrid cloud environments, is affected by multiple security flaws. An attacker with basic user permissions can inject malicious scripts into shared components like policies or dashboards. If an administrator views these components, the attacker could potentially hijack their session to perform unauthorized administrative actions, leading to full system compromise.
Technical details
VMware Cloud Foundation Operations (formerly Aria Operations) contains multiple stored cross-site scripting (XSS) vulnerabilities. The root cause is improper sanitization of user-supplied input within policies, views, and text-widgets. An attacker with low-privileged access (PR:L) can inject malicious JavaScript that executes in the context of other users, including administrators, when they interact with the affected components (UI:R). Successful exploitation allows the attacker to perform administrative actions, potentially leading to a complete compromise of confidentiality, integrity, and availability. Patches are available in versions 9.1.0.0, 9.0.2.0 EP2, and 8.18.7 depending on the specific product deployment.
Affected products
- VMware Cloud Foundation Operations 9.1.x, 9.0.x, 5.x
- VMware Aria Operations 8.x, 5.x
- VMware vSphere Foundation 9.1.x, 9.0.x
- VMware Telco Cloud Platform 5.x
Timeline
- 2026-06-08: disclosed: Initial publication of VMSA-2026-0004
- 2026-06-08: patched