CVE-2026-41722 Details
Description
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
Multiple stored cross-site scripting vulnerabilities have been identified in VMware Cloud Foundation Operations. A malicious actor with the ability to create policies, views, or text widgets could inject scripts to execute administrative actions within the application. These vulnerabilities are present in VMware Cloud Foundation 9.0.x.x, 9.1.x.x, and VMware Aria Operations versions 8.x.
Users can upgrade to VMware Cloud Foundation 9.1.0.0 or 9.0.2.0 EP2. VMware Aria Operations users should upgrade to version 8.18.7 or 8.18.6. For VMware Cloud Foundation 5.x or VMware Telco Cloud Platform 5.x, consult the respective Broadcom knowledge articles.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37513 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| vmware aria operations | >= 8.0, < 8.18.7 |
CPE
Remediation
| |
| vmware cloud foundation | >= 5.0, < 8.18.7 >= 9.0, < 9.0.2.0 9.1 - |
CPE
Remediation
| |
| vmware telco cloud platform | >= 5.0, <= 5.1 |
CPE
Remediation
| |
| vmware vsphere | >= 9.0, < 9.0.2.0 9.1 - |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 9, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | New CVE Received | [email protected] |