CVE-2026-41722: VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove or limit the privilege to create policies, views, or text-widgets to only trusted administrator roles and accounts that require it.
VMware Cloud Foundation Operations - user privileges create policies/views/text-widgets privilege = restricted to trusted administrators - Compensating control
Enable auditing and monitoring for creation or modification of policies, views, and text-widgets and alert on suspicious or unexpected changes to detect possible injected scripts.
- Operational
Review existing policies, views, and text-widgets for injected scripts or malicious content and remove or sanitize any discovered items.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41722?
CVE-2026-41722 has a high severity rating of 8.
How do I fix CVE-2026-41722?
To fix CVE-2026-41722, apply the latest updates provided by VMware for Cloud Foundation Operations.
What type of vulnerability is CVE-2026-41722?
CVE-2026-41722 is a stored cross-site scripting vulnerability affecting VMware Cloud Foundation Operations.
Who is affected by CVE-2026-41722?
Users with privileges to create policies, views, or text-widgets in VMware Cloud Foundation Operations are affected by CVE-2026-41722.
What actions can be performed due to CVE-2026-41722?
A malicious actor could inject scripts to perform administrative actions within VMware Cloud Foundation Operations.