Description
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
Published: 2026-07-30
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in VMware ESX is an insufficient logging flaw that can be exploited by a malicious administrator to carry out certain operations without those actions being recorded in the system logs. This allows privileged users to evade detection and maintain a false sense of audit compliance, potentially masking malicious changes or policy violations.

Affected Systems

The affected technologies include VMware:Cloud Foundation, VMware:ESX, VMware:Telco Cloud Platform, and VMware:vSphere Foundation. No specific version information is provided, so any deployment of these products that has not applied the latest security update may be vulnerable.

Risk and Exploitability

With a CVSS score of 2.7, the flaw is considered low severity, and the EPSS score of 0.38% indicates a very low but non‑zero exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is an internal malicious administrator who already has elevated privileges within the environment; such a user can exploit the lack of logging to perform unlogged actions. The overall risk is therefore low, but it undermines audit integrity and accounts for potential internal misuse.

Generated by OpenCVE AI on August 2, 2026 at 05:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest VMware ESX patch or upgrade to a version where the logging issue is resolved.
  • Deploy an external audit logging solution that captures privileged actions independently of the system logs.
  • Enforce least privilege by limiting administrative access to only those users who require it for operations.

Generated by OpenCVE AI on August 2, 2026 at 05:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware cloud Foundation
Vmware esx
Vmware telco Cloud Platform
Vmware vsphere Foundation
Vendors & Products Vmware
Vmware cloud Foundation
Vmware esx
Vmware telco Cloud Platform
Vmware vsphere Foundation

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
Title ESX insufficient logging vulnerability
Weaknesses CWE-778
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Vmware Cloud Foundation Esx Telco Cloud Platform Vsphere Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-30T15:10:15.160Z

Reserved: 2026-04-22T06:21:34.490Z

Link: CVE-2026-41709

cve-icon Vulnrichment

Updated: 2026-07-30T15:10:11.808Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-30T14:16:57.420

Modified: 2026-07-30T19:07:59.843

Link: CVE-2026-41709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:30:06Z

Weaknesses