CVE-2026-59309

Critique9.8Publiée le 30 juillet 2026

VMware vCenter contient une vulnérabilité de contournement d'authentification dans VMware Directory Service. Un acteur malveillant ayant un accès réseau à vCenter peut exploiter ce problème pour contourner l'authentification et obtenir un accès non autorisé au système.

Score CVSS9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Type de faiblesse (CWE)CWE-303
Éditeursvmware

Produits concernés

ÉditeursProduitVersions
vmwarevcenter server< 8.0
vmwaretelco cloud infrastructure3.0
vmwaretelco cloud platform<= 5.2
vmwarecloud foundation-
vmwarevsphere foundation-

Articles liés

This product uses the NVD API but is not endorsed or certified by the NVD.

La description technique est notre traduction du texte original du NVD, en anglais.

Base de données CVE