CVE-2026-59309

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

Scoring

Severity
CRITICAL
CVSS base score
9.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS probability
7.94%
CWE
CWE-303
Published
2026-07-30
Last modified
2026-07-30

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs