VDB

GCVE-110-NCSC-2026-70

GCVE-110-NCSC-2026-70
Advisory PublishedCVSS 6.2/10
Vulnetix · Advisory published February 25, 2026
VMware Aria Operations contains a privilege escalation vulnerability allowing users with vCenter access to gain administrative privileges, rated Moderate severity with a CVSSv3 score of 6.2, as detailed in VMSA-2026-0001.

Weaknesses (CWE)

CWE-269Improper Privilege ManagementCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')

Risk Scores

CVSS 3.1
6.2/10
Medium · CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L

Affected Products

VendorProductVersionsPlatforms
VMwarevers:unknown/*

References

advisory
advisory
exploit
advisory
advisory
advisory

Browse GCVE Records

74,496 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›