VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware aria Operations Vmware telco Cloud Platform Vmware vcf Operations |
|
| Vendors & Products |
Vmware
Vmware aria Operations Vmware telco Cloud Platform Vmware vcf Operations |
Mon, 08 Jun 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Mon, 08 Jun 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. | |
| Title | VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published: 2026-06-08T07:06:11.548Z
Updated: 2026-06-09T11:52:17.283Z
Reserved: 2026-04-22T06:21:37.021Z
Link: CVE-2026-41723
Updated: 2026-06-08T10:29:16.158Z
Status : Undergoing Analysis
Published: 2026-06-08T09:16:30.567
Modified: 2026-06-09T13:16:36.260
Link: CVE-2026-41723
No data.