VMware vCenter Auth Bypass in Directory Service
CVE-2026-59309 Published on July 30, 2026
vCenter authentication-bypass vulnerability
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Vulnerability Analysis
CVE-2026-59309 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
Incorrect Implementation of Authentication Algorithm
The requirements for the software dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect. This incorrect implementation may allow authentication to be bypassed.
Products Associated with CVE-2026-59309
Want to know whenever a new CVE is published for VMware products? stack.watch will email you.
Affected Versions
VMware Cloud Foundation:- Version 9.1.x.x is affected.
- Version 9.0.x.x is affected.
- Version 5.x is affected.
- Version 9.1.x.x is affected.
- Version 9.0.x.x is affected.
- Version 9.1.x.x and below 9.1.0.0300 is affected.
- Version 9.0.x.x and below 9.0.2.0100 is affected.
- Version 8.0 and below 8.0 U3k is affected.
- Version 3.0 is affected.
- Version 5.1.x is affected.
- Version 5.0.x is affected.
- Version 4.x is affected.
- Version 3.0 is affected.