CVE-2026-59309

VMware · Cloud Foundation, vCenter, vSphere Foundation, Telco Cloud Infrastructure, Telco Cloud Platform

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service, allowing unauthenticated attackers with network access to gain unauthorized system access.

Executive summary

An authentication bypass vulnerability in the VMware Directory Service allows unauthenticated remote attackers to gain full system access, presenting a critical security risk.

Vulnerability

This is an authentication bypass flaw (CWE-303) within the VMware Directory Service. The vulnerability allows an attacker with network access to vCenter to bypass authentication mechanisms entirely, requiring no prior user credentials.

Business impact

A successful exploit grants an attacker unauthorized access to the vCenter environment, which typically manages the entire virtual infrastructure. Given the CVSS score of 9.8, this vulnerability poses a total risk to confidentiality, integrity, and availability, potentially leading to full administrative control over virtual machines, data exfiltration, and significant operational disruption.

Remediation

Immediate Action: Apply the vendor-supplied updates immediately by upgrading to the patched versions specified in the Broadcom support advisory.

Proactive Monitoring: Monitor network traffic for unusual authentication requests to the VMware Directory Service and review vCenter access logs for unauthorized administrative activity.

Compensating Controls: Restrict network access to the vCenter management interface to trusted management networks only, utilizing firewall rules to block unauthorized external access.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability is critical and requires immediate attention due to the ease of exploitation and the potential for total system compromise. Organizations must prioritize patching their VMware environments to the latest versions defined in the vendor advisory to mitigate this high-severity risk.