CVE-2026-41709
2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Summary
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| VMware | Cloud Foundation | 9.1.x.x | affected |
| VMware | Cloud Foundation | 9.0.x.x | affected |
| VMware | Cloud Foundation | 5.x < 5.2.4 | affected |
| VMware | vSphere Foundation | 9.1.x.x | affected |
| VMware | vSphere Foundation | 9.0.x.x | affected |
| VMware | ESX | 9.1.x.x < ESXi-9.1.0.0-25370933 | affected |
| VMware | ESX | 9.0.x.x < ESXi-9.0.2.0100-25595025 | affected |
| VMware | ESX | 8.0 < ESXi80U3j-25429389 | affected |
| VMware | Telco Cloud Platform | 5.1.x | affected |
| VMware | Telco Cloud Platform | 5.0.x | affected |
Weaknesses
- CWE-778: CWE-778 Insufficient logging
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.