Vulnerability Description
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Aria Operations | >= 8.0, < 8.18.7 |
| Vmware | Cloud Foundation | >= 5.0, < 8.18.7 |
| Vmware | Telco Cloud Platform | >= 5.0, <= 5.1 |
| Vmware | Vsphere | >= 9.0, < 9.0.2.0 |
Related Weaknesses (CWE)
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/conThird Party Advisory
FAQ
What is CVE-2026-41722?
CVE-2026-41722 is a vulnerability with a CVSS score of 8.0 (HIGH). VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scrip...
How severe is CVE-2026-41722?
CVE-2026-41722 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41722?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Aria Operations, Vmware Cloud Foundation, Vmware Telco Cloud Platform, Vmware Vsphere.