VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware vcenter Server
|
|
| CPEs | cpe:2.3:a:vmware:cloud_foundation:-:*:*:*:*:*:*:* cpe:2.3:a:vmware:telco_cloud_infrastructure:3.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update1e:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update2d:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update2e:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update3:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update3a:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update3b:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update3c:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update3d:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update3e:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update3g:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update3h:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update3i:*:*:*:*:*:* cpe:2.3:a:vmware:vcenter_server:8.0:update3j:*:*:*:*:*:* cpe:2.3:a:vmware:vsphere_foundation:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vmware vcenter Server
|
Thu, 30 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware cloud Foundation Vmware telco Cloud Infrastructure Vmware telco Cloud Platform Vmware vcenter Vmware vsphere Foundation |
|
| Vendors & Products |
Vmware
Vmware cloud Foundation Vmware telco Cloud Infrastructure Vmware telco Cloud Platform Vmware vcenter Vmware vsphere Foundation |
Thu, 30 Jul 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. | |
| Title | vCenter authentication-bypass vulnerability | |
| Weaknesses | CWE-303 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published: 2026-07-30T12:19:52.390Z
Updated: 2026-07-30T15:08:05.176Z
Reserved: 2026-07-04T18:13:57.026Z
Link: CVE-2026-59309
Updated: 2026-07-30T15:08:00.799Z
Status : Analyzed
Published: 2026-07-30T13:16:53.870
Modified: 2026-08-25T18:12:14.410
Link: CVE-2026-59309
No data.