nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-41722 CVE-2026-41722
HIGH
VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)
Record summary
CVE-2026-41722 has a selected CVSS score of 8.0 (high).
Description
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 9, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
VCF operationsBrowse VMware / VCF operationsDefault status: affected | CVE List | 9.1.x.x to ≤ 9.1.0.0 | affected |
| 9.0.x.x to ≤ 9.0.2.0 EP2 | affected | ||
| 5.x to ≤ 8.18.7 | affected | ||
VMware Aria OperationsBrowse VMware / VMware Aria OperationsDefault status: affected | CVE List | 8.18.x to ≤ 8.18.6 | affected |
| 8.18.x to ≤ 8.18.7 | affected | ||
VMware Telco Cloud PlatformBrowse VMware / VMware Telco Cloud PlatformDefault status: affected | CVE List | 5.x to ≤ 8.18.7 | affected |
References
2support.broadcom.com
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37513