Vulnerability Details CVE-2026-41722
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 17.7%
CVSS Severity
CVSS v3 Score 8.0
Products affected by CVE-2026-41722
-
cpe:2.3:a:vmware:aria_operations:8.0
-
cpe:2.3:a:vmware:aria_operations:8.10.0
-
cpe:2.3:a:vmware:aria_operations:8.12.0
-
cpe:2.3:a:vmware:aria_operations:8.14.0
-
cpe:2.3:a:vmware:aria_operations:8.14.1
-
cpe:2.3:a:vmware:aria_operations:8.16.0
-
cpe:2.3:a:vmware:aria_operations:8.16.1
-
cpe:2.3:a:vmware:aria_operations:8.17.1
-
cpe:2.3:a:vmware:aria_operations:8.17.2
-
cpe:2.3:a:vmware:aria_operations:8.18
-
cpe:2.3:a:vmware:aria_operations:8.18.1
-
cpe:2.3:a:vmware:aria_operations:8.18.2
-
cpe:2.3:a:vmware:aria_operations:8.18.3
-
cpe:2.3:a:vmware:aria_operations:8.18.4
-
cpe:2.3:a:vmware:aria_operations:8.18.5
-
cpe:2.3:a:vmware:aria_operations:8.6.0
-
cpe:2.3:a:vmware:cloud_foundation:5.0
-
cpe:2.3:a:vmware:cloud_foundation:5.1
-
cpe:2.3:a:vmware:cloud_foundation:5.1.1
-
cpe:2.3:a:vmware:cloud_foundation:5.2
-
cpe:2.3:a:vmware:cloud_foundation:5.2.1
-
cpe:2.3:a:vmware:cloud_foundation:5.2.1.1
-
cpe:2.3:a:vmware:cloud_foundation:5.2.1.2
-
cpe:2.3:a:vmware:cloud_foundation:5.2.2
-
cpe:2.3:a:vmware:cloud_foundation:9.0
-
cpe:2.3:a:vmware:cloud_foundation:9.0.1.0
-
cpe:2.3:a:vmware:cloud_foundation:9.1
-
cpe:2.3:a:vmware:telco_cloud_platform:5.0
-
cpe:2.3:a:vmware:telco_cloud_platform:5.0.1
-
cpe:2.3:a:vmware:vsphere:*
-
cpe:2.3:a:vmware:vsphere:9.1