Insufficient Logging Vulnerability in VMware ESX
CVE-2026-41709

2.7LOW

Key Information:

Vendor

Vmware

Vendor
CVE Published:
30 July 2026

What is CVE-2026-41709?

VMware ESX contains a vulnerability characterized by insufficient logging capabilities. This flaw allows a malicious administrator to execute specific actions without those actions being recorded in the logs. Such a lack of traceability may lead to a higher risk of exploitation, enabling unauthorized activities to go unnoticed. Organizations using VMware ESX should assess their logging practices to mitigate potential security risks.

Affected Version(s)

Cloud Foundation 9.1.x.x

Cloud Foundation 9.0.x.x

Cloud Foundation 5.x < 5.2.4

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.