Skip to finding
important · Remote code execution

Patch analysis demonstrates two independent pre-authentication routes into VMware vCenter.

Affects

VMware vCenter Server Appliance, the virtualization-management control plane deployed in vSphere and VMware Cloud Foundation environments.

One route uses a crafted SRP value to authenticate to vmdir as an existing identity without its password. The other uses traversal in syslog fields for arbitrary file write; researchers reached code execution but withheld the final sink. Broadcom has fixed builds, while pre-fix image acceptance and revocation completeness remain unknown.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 22, 2026