CVE-2026-59309

Summary

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

Affected Software

VendorProductVersion RangeStatus
VMwareCloud Foundation9.1.x.xaffected
VMwareCloud Foundation9.0.x.xaffected
VMwareCloud Foundation5.xaffected
VMwarevSphere Foundation9.1.x.xaffected
VMwarevSphere Foundation9.0.x.xaffected
VMwarevCenter9.1.x.x < 9.1.0.0300affected
VMwarevCenter9.0.x.x < 9.0.2.0100affected
VMwarevCenter8.0 < 8.0 U3kaffected
VMwareTelco Cloud Infrastructure3.0affected
VMwareTelco Cloud Platform5.1.xaffected
VMwareTelco Cloud Platform5.0.xaffected
VMwareTelco Cloud Platform4.xaffected
VMwareTelco Cloud Platform3.0affected

Weaknesses

  • CWE-303: CWE-303 Incorrect implementation of authentication algorithm

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References