VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 15 May 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware fusion
Vendors & Products Vmware
Vmware fusion

Fri, 15 May 2026 07:00:00 +0000

Type Values Removed Values Added
Description VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.
Title TOCTOU local privilege escalation vulnerability
Weaknesses CWE-367
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-05-15T06:11:38.418Z

Reserved: 2026-04-22T06:21:22.982Z

Link: CVE-2026-41702

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-15T07:16:18.923

Modified: 2026-05-15T07:16:18.923

Link: CVE-2026-41702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-15T08:30:40Z

Weaknesses