Database/Control plane, storage & DevOps
VMware vCenter Server (authenticated command execution via alarms): A user with permission to create or modify alarms
Impact
A user with permission to create or modify alarms and run script actions executes arbitrary commands on vCenter. The alarm/script-action feature is a legitimate automation path that doubles as a privilege-escalation route to root on the management server.
Who can reach it
Authenticated vCenter user holding alarm-management privileges - a role commonly granted to monitoring integrations.
What to do
Apply the Broadcom fix per advisory 25717. Also audit which service accounts hold alarm/script-action rights; most monitoring integrations do not need them.
References
Related entries
- N-able N-central: Improper input validationCVE-2025-8876 · N-able N-centralHigh
- Grafana: symlink escape in plugin archive extraction gives remote code execution as the Grafana processCVE-2026-15815 · Grafana OSS / Enterprise (plugin archive extraction)High
- Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole): The RHOAI overlayCVE-2026-18951 · Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole)High
- NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID): An attacker who already has valid credentialsCVE-2026-22049 · NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID)High
- Jenkins: symlinks in tar archives let a job or agent write files anywhere the controller canCVE-2026-33001 · Jenkins controller (.tar/.tar.gz extraction, symlink handling)High
- Apache ActiveMQ: Improper input validation and code injection in the brokerCVE-2026-34197 · Apache ActiveMQHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.