Executive brief
VMware vCenter, a centralized management platform for virtualized environments, contains a critical security flaw in its directory service. An attacker with network access to the management interface can bypass security checks to gain full unauthorized access to the system. This could allow an attacker to take control of the entire virtual infrastructure, leading to data theft, service disruption, or further attacks on hosted virtual machines.
Technical details
An authentication bypass vulnerability exists in the VMware Directory Service (vmdir) component of VMware vCenter Server. The flaw is classified as an incorrect implementation of an authentication algorithm (CWE-303). A remote, unauthenticated attacker with network access to the vCenter Server can exploit this vulnerability to bypass authentication mechanisms and gain administrative access to the management platform. This provides the attacker with high-level privileges over the vSphere environment, including the ability to manage hosts and virtual machines. Patches have been released for affected versions including 8.0, 9.0, and 9.1.
Affected products
- VMware vCenter Server 9.1.x.x before 9.1.0.0300, 9.0.x.x before 9.0.2.0100, 8.0 before 8.0 U3k
- VMware Cloud Foundation 9.1.x.x, 9.0.x.x, 5.x
- VMware vSphere Foundation 9.1.x.x, 9.0.x.x
- VMware Telco Cloud Platform 5.1.x, 5.0.x, 4.x, 3.0
- VMware Telco Cloud Infrastructure 3.0
Timeline
- 2026-07-29: advisory: Initial advisory VMSA-2026-0006 published by Broadcom
- 2026-07-30: disclosed: CVE-2026-59309 published to NVD