Path traversal in vCenter Server - CVE-2026-59310

 

Path traversal in vCenter Server - CVE-2026-59310

Published: July 30, 2026 / Updated: August 14, 2026


Vulnerability identifier: #VU140094
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59310
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in the Syslog server. A remote non-authenticated attacker can send a specially crafted HTTP request and read arbitrary files on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise the entire system.


Affected software

vCenter Server

How to mitigate CVE-2026-59310

Install updates from vendor's website.

vCenter Server - update to 8.0 U3k

External References

Related Security Bulletins