CVE-2026-41723: VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Restrict which users/roles can create policies, views, or text-widgets; remove this capability from accounts that do not require it. Apply VMware Cloud Foundation Operations updates that address these vulnerabilities as soon as they are available.
VMware Cloud Foundation Operations creation_privileges_for_policies_views_text-widgets = limit_to_trusted_administrators_only
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41723?
The severity of CVE-2026-41723 is rated as high with a score of 8.
How do I fix CVE-2026-41723?
To fix CVE-2026-41723, ensure that VMware Cloud Foundation Operations is updated to the latest version provided in the security advisory.
What type of vulnerability is CVE-2026-41723?
CVE-2026-41723 is a stored cross-site scripting vulnerability.
Who is affected by CVE-2026-41723?
Users with privileges to create policies, views, or text-widgets in VMware Cloud Foundation Operations are affected by CVE-2026-41723.
What impact does CVE-2026-41723 have?
CVE-2026-41723 allows a malicious actor to inject scripts that can perform unauthorized administrative actions in VMware Cloud Foundation Operations.