Description
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Published: 2026-07-30
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass allowing unauthorized access
Action: Immediate patch
AI Analysis

Impact

VMware vCenter contains an authentication bypass flaw in the VMware Directory Service. A malicious actor who can reach the vCenter management interface over the network can exploit this weakness to bypass authentication and gain unauthorized access to the system. The CWE-303 weakness undermines fundamental authorization checks, allowing an attacker to assume any user identity without providing credentials. The impact is that the attacker can perform operations available to the authenticated user, potentially accessing or modifying system resources and data. The description does not specify further capabilities beyond the bypass itself.

Affected Systems

Affected vendors include VMware. Impacted products are Cloud Foundation, Telco Cloud Infrastructure, Telco Cloud Platform, vCenter Server, and vSphere Foundation. Affected versions include vCenter Server 8.0 and all its subsequent releases up to and including update3j, as well as the various minor updates listed (e.g., update1, update1a, update1b, update1c, update1d, update1e, update1*, update2a, update2b, update2c, update2d, update2e, update3a, update3b, update3c, update3d, update3e, update3g, update3h, update3i, update3j). Telco Cloud Infrastructure 3.0 is also affected. Cloud Foundation and vSphere Foundation are affected in all releases as indicated by the CPE strings.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score is reported as < 1%, showing a very low probability of exploitation in the wild, although the lack of KEV listing does not reduce potential damage. An attacker only needs network access to the vCenter management interface; no additional privileges are required before exploitation. After the authentication bypass is achieved, the attacker can carry out any actions that are permitted for the user account they assume. The direct attack path is straightforward, but the high impact warrants immediate action.

Generated by OpenCVE AI on September 24, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to the latest version that contains the fix for the Directory Service authentication bypass.
  • Limit network exposure of the vCenter server by implementing segmentation or firewall rules that allow traffic only from trusted hosts or subnets and disabling any unnecessary management protocols.
  • Enable and regularly review audit logging for authentication events, enforce least privilege on vCenter roles, and consider enabling multi‑factor authentication to reduce the risk of credential misuse.

Generated by OpenCVE AI on September 24, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Vmware vcenter Server
CPEs cpe:2.3:a:vmware:cloud_foundation:-:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_infrastructure:3.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update1e:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update2d:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update2e:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update3:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update3a:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update3b:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update3c:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update3d:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update3e:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update3g:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update3h:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update3i:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_server:8.0:update3j:*:*:*:*:*:*
cpe:2.3:a:vmware:vsphere_foundation:-:*:*:*:*:*:*:*
Vendors & Products Vmware vcenter Server

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware cloud Foundation
Vmware telco Cloud Infrastructure
Vmware telco Cloud Platform
Vmware vcenter
Vmware vsphere Foundation
Vendors & Products Vmware
Vmware cloud Foundation
Vmware telco Cloud Infrastructure
Vmware telco Cloud Platform
Vmware vcenter
Vmware vsphere Foundation

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Title vCenter authentication-bypass vulnerability
Weaknesses CWE-303
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Vmware Cloud Foundation Telco Cloud Infrastructure Telco Cloud Platform Vcenter Vcenter Server Vsphere Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-30T15:08:05.176Z

Reserved: 2026-07-04T18:13:57.026Z

Link: CVE-2026-59309

cve-icon Vulnrichment

Updated: 2026-07-30T15:08:00.799Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T13:16:53.870

Modified: 2026-08-25T18:12:14.410

Link: CVE-2026-59309

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T23:15:21Z

Weaknesses
  • CWE-303

    Incorrect Implementation of Authentication Algorithm