VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
References
| Link | Resource |
|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37513 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
15 Jun 2026, 18:50
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Vmware aria Operations
Vmware Vmware cloud Foundation Vmware telco Cloud Platform |
|
| CPE | cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* |
|
| References | () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37513 - Third Party Advisory |
09 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 |
08 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-08 09:16
Updated : 2026-06-17 10:47
NVD link : CVE-2026-41724
Mitre link : CVE-2026-41724
CVE.ORG link : CVE-2026-41724
JSON object : View
Products Affected
vmware
- telco_cloud_platform
- cloud_foundation
- aria_operations
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
