Database/Control plane, storage & DevOps
VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissions
CVSS 8.5CVE-2025-41250Control plane, storage & DevOpscurated
Impact
A non-administrative user with scheduled-task permissions manipulates vCenter notification emails - useful for phishing operators with mail that genuinely originates from vCenter.
Who can reach it
Authenticated low-privilege vCenter user able to create scheduled tasks.
What to do
Apply the Broadcom fix per advisory 36150. vCenter patch; low urgency relative to the RCE issues but it enables convincing internal phishing.
References
Related entries
- AMD NBIO register lock bits - System Management Network access: NBIO registers that should be locked after boot areCVE-2025-61972 · AMD NBIO register lock bits - System Management Network accessHigh
- Pure Storage FlashBlade logging: Sensitive material ends up in FlashBlade logs under certain conditions, and the scoredCVE-2026-0207 · Pure Storage FlashBlade loggingHigh
- GitLab package registry: authenticated path traversal that can lead to remote code executionCVE-2026-10053 · GitLab CE/EE package registryHigh
- GitLab: developer-role user can run pipelines on a protected branch without push rightsCVE-2026-15423 · GitLab CE/EE (CI/CD pipeline reference authorization)High
- GitLab EE: authenticated user can attribute AI usage to another namespaceCVE-2026-19228 · GitLab EE (AI feature usage attribution / request identity authorization)High
- open-iscsi / open-isns - iscsiuio control socket authorization and iSNS record handling: Three related defectsCVE-2026-44944 · open-iscsi / open-isns - iscsiuio control socket authorization and iSNS record handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.