CVE-2026-41724: VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch VMSA-2026-0004 - Configuration
Restrict privileges to create policies, views, or text-widgets to a minimal set of trusted administrators until the VMSA-2026-0004 update can be applied.
VMware Cloud Foundation Operations policy/view/text-widget creation privileges = limited to trusted administrators - Operational
Audit existing policies, views, and text-widgets for injected scripts or unauthorized content and remove or sanitize any suspicious entries; monitor for signs of exploitation until the update is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41724?
CVE-2026-41724 has a severity rating of high with a score of 8.
How do I fix CVE-2026-41724?
To remediate CVE-2026-41724, ensure that you apply the latest updates for VMware Cloud Foundation Operations as indicated in the security advisory.
What type of vulnerability is CVE-2026-41724?
CVE-2026-41724 is categorized as a stored cross-site scripting vulnerability.
Who is affected by CVE-2026-41724?
Users with privileges to create policies, views or text-widgets in VMware Cloud Foundation Operations are affected by CVE-2026-41724.
What actions can be exploited through CVE-2026-41724?
A malicious actor may exploit CVE-2026-41724 to inject scripts that perform unauthorized administrative actions.