Description
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Published: 2026-07-30
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

VMware vCenter contains an authentication bypass flaw in the VMware Directory Service. An attacker who can reach the vCenter management interface over the network can exploit this weakness to log in as any user without providing credentials. This CWE-303 weakness undermines fundamental authorization checks, giving the attacker full control over the vCenter console and all virtualized workloads it manages. The result is unrestricted ability to create, modify, and delete virtual machines, expose or exfiltrate data, and potentially pivot to other hosts, thus threatening confidentiality, integrity, and availability across the infrastructure.

Affected Systems

Affected vendors include VMware; products impacted are Cloud Foundation, Telco Cloud Infrastructure, Telco Cloud Platform, vCenter, and vSphere Foundation. No specific version numbers are listed in the advisory, so any installation of these products that has not yet applied the vendor's fix remains vulnerable.

Risk and Exploitability

The CVSS score of 9.8 demonstrates a critical level of severity. The EPSS score is reported as less than 1%, indicating a low probability of exploitation in the wild, yet the lack of KEV listing does not mitigate the potential damage. An attacker only needs network access to the vCenter management interface; no special privileges are required prior to exploitation. Once the authentication bypass is achieved, the attacker can perform any operation supported by vCenter, effectively gaining comprehensive control over the virtual environment. Although the exploitation path is straightforward, the high impact warrants immediate action.

Generated by OpenCVE AI on August 3, 2026 at 10:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to the latest version that contains the fix for the Directory Service authentication bypass.
  • Limit network exposure of the vCenter server by implementing segmentation or firewall rules that allow traffic only from trusted hosts or subnets and disabling any unnecessary management protocols.
  • Enable and regularly review audit logging for authentication events, enforce least privilege on vCenter roles, and consider enabling multi‑factor authentication to reduce the risk of credential misuse.

Generated by OpenCVE AI on August 3, 2026 at 10:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware cloud Foundation
Vmware telco Cloud Infrastructure
Vmware telco Cloud Platform
Vmware vcenter
Vmware vsphere Foundation
Vendors & Products Vmware
Vmware cloud Foundation
Vmware telco Cloud Infrastructure
Vmware telco Cloud Platform
Vmware vcenter
Vmware vsphere Foundation

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Title vCenter authentication-bypass vulnerability
Weaknesses CWE-303
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Vmware Cloud Foundation Telco Cloud Infrastructure Telco Cloud Platform Vcenter Vsphere Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-30T15:08:05.176Z

Reserved: 2026-07-04T18:13:57.026Z

Link: CVE-2026-59309

cve-icon Vulnrichment

Updated: 2026-07-30T15:08:00.799Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-30T13:16:53.870

Modified: 2026-07-30T16:17:15.073

Link: CVE-2026-59309

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:00:03Z

Weaknesses
  • CWE-303

    Incorrect Implementation of Authentication Algorithm