VMware vCenter Auth Bypass in Directory Service
CVE-2026-59309 Published on July 30, 2026

vCenter authentication-bypass vulnerability
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

NVD

Vulnerability Analysis

CVE-2026-59309 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Incorrect Implementation of Authentication Algorithm

The requirements for the software dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect. This incorrect implementation may allow authentication to be bypassed.


Products Associated with CVE-2026-59309

Want to know whenever a new CVE is published for VMware products? stack.watch will email you.

 
 
 

Affected Versions

VMware Cloud Foundation: VMware vSphere Foundation: VMware vCenter: VMware Telco Cloud Infrastructure: VMware Telco Cloud Platform: