CVE-2026-59310

Summary

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Affected Software

VendorProductVersion RangeStatus
VMwareCloud Foundation9.1.x.xaffected
VMwareCloud Foundation9.0.x.xaffected
VMwareCloud Foundation5.xaffected
VMwarevSphere Foundation9.1.x.xaffected
VMwarevSphere Foundation9.0.x.xaffected
VMwarevCenter9.1.x.x < 9.1.0.0300affected
VMwarevCenter9.0.x.x < 9.0.2.0100affected
VMwarevCenter8.0 < 8.0 U3kaffected
VMwareTelco Cloud Infrastructure3.0affected
VMwareTelco Cloud Platform5.1.xaffected
VMwareTelco Cloud Platform5.0.xaffected
VMwareTelco Cloud Platform4.xaffected
VMwareTelco Cloud Platform3.0affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References