VULNERABILITY OVERVIEW
Published July 29, 2026 as part of VMSA-2026-0006, this critical authentication bypass in the VMware Directory Service allows a remote unauthenticated attacker with network access to vCenter to bypass authentication controls and gain unauthorized full access to the management platform. Since vCenter centrally manages ESXi hosts, VMs, and permissions across datacenter infrastructure, successful exploitation provides a high-value pivot point for lateral movement. No workaround is available; no in-the-wild exploitation confirmed by Broadcom at time of publication.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
VMware Cloud Foundation/vSphere Foundation 9.1.x (fixed in 9.1.0.0300), 9.0.x (fixed in 9.0.2.0100), 8.0 U3k; also vCenter 5.xCITATIONS
- → https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
- → https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
- → https://gbhackers.com/critical-vmware-vcenter-flaws/amp/
- → https://cybersecuritynews.com/vmware-flaws-allow-authentication-bypass/