CVE-2017-4926: VMware vCenter Server

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.

Affected products

  • VMware vCenter Server: version 6.5 only

Published 2017-09-15. Last modified 2026-06-17.