nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-41724 CVE-2026-41724
HIGH
VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)
Record summary
CVE-2026-41724 has a selected CVSS score of 8.0 (high).
Description
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 9, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
VCF operationsBrowse VMware / VCF operationsDefault status: affected | CVE List | 5.x to ≤ 8.18.7 | affected |
VMware Aria OperationsBrowse VMware / VMware Aria OperationsDefault status: affected | CVE List | 8.18.x to ≤ 8.18.7 | affected |
VMware Telco Cloud PlatformBrowse VMware / VMware Telco Cloud PlatformDefault status: affected | CVE List | 5.x to ≤ 8.18.7 | affected |
References
2support.broadcom.com
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37513