VMware Cloud Foundation Missing Authorisation Vulnerability
Description
VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A missing authorization vulnerability in VMware Cloud Foundation allows an authenticated appliance user to perform unauthorized actions and access limited sensitive information.
Vulnerability
VMware Cloud Foundation contains a missing authorization vulnerability (CVE-2025-41231). The flaw allows a malicious actor with access to the VMware Cloud Foundation appliance to perform certain unauthorized actions and access limited sensitive information. The specific component and exact conditions required to reach the vulnerable code path have not been disclosed in the advisory. Affected versions include VMware Cloud Foundation deployments prior to the updates specified in VMSA-2025-0009 [1].
Exploitation
An attacker must have access to the VMware Cloud Foundation appliance, implying a prior foothold or authenticated access. The advisory does not detail the precise steps or attack vector required to trigger the missing authorization. The vulnerability is distinct from CVE-2025-41229 (directory traversal) and CVE-2025-41230 (information disclosure), which require network access to port 443 [1].
Impact
Successful exploitation enables the attacker to perform actions that should be restricted and access limited sensitive information. The level of privilege achieved and the nature of the unauthorized actions are not fully described, but the CVSSv3 base score range for the advisory is 7.3-8.2, indicating high severity [1].
Mitigation
Broadcom (VMware) has released updates to remediate this vulnerability. The fixed versions are listed in the 'Fixed Version' column of the Response Matrix in VMSA-2025-0009 [1]. No workarounds are available. Affected users should apply the updates as soon as possible.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.