Record summary

CVE-2026-41722 has a selected CVSS score of 8.0 (high).

Description

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 9, 2026 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: affected

CVE List9.1.x.x to ≤ 9.1.0.0affected
9.0.x.x to ≤ 9.0.2.0 EP2affected
5.x to ≤ 8.18.7affected

Default status: affected

CVE List8.18.x to ≤ 8.18.6affected
8.18.x to ≤ 8.18.7affected

Default status: affected

CVE List5.x to ≤ 8.18.7affected

References

2