Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-59309: VMware vCenter Authentication Bypass Risk
CVE-2026-59309 · published 2 months ago
Summary
VMware vCenter's authentication system has a weakness that could allow an attacker with network access to bypass security checks and access the system without a valid login. This could lead to unauthorized access to sensitive information and potential system compromise. To mitigate this risk, ensure VMware vCenter is properly configured and patched with the latest security updates.
What to do
- Update vmware vcenter to version 9.1.0.0300 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vmware | cloud foundation | 9.1.x.x |
| vmware | vsphere foundation | 9.1.x.x |
| vmware | vcenter | < 9.1.0.0300 |
| vmware | telco cloud infrastructure | 3.0 |
| vmware | telco cloud platform | 5.1.x |
Original advisory text
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and ...
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-303Incorrect Implementation of Authentication Algorithm
Timeline
Published30 Jul 2026
Updated27 Sep 2026
First seen30 Jul 2026
Track software like this
Free during beta