Cross-site scripting in VMware Aria Operations (formerly vRealize Operations) - CVE-2026-41724
Published: June 12, 2026
VMware Aria Operations (formerly vRealize Operations)
Detailed vulnerability description
The vulnerability allows a remote user to inject arbitrary script code and perform administrative actions.
The vulnerability exists due to cross-site scripting in VMware Cloud Foundation Operations when handling stored content in policies, views, or text-widgets. A remote user can inject scripts to perform administrative actions.
User interaction is required.