VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.
History

Fri, 15 May 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 15 May 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware fusion
Vendors & Products Vmware
Vmware fusion

Fri, 15 May 2026 07:00:00 +0000

Type Values Removed Values Added
Description VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.
Title TOCTOU local privilege escalation vulnerability
Weaknesses CWE-367
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-05-15T09:52:56.934Z

Reserved: 2026-04-22T06:21:22.982Z

Link: CVE-2026-41702

cve-icon Vulnrichment

Updated: 2026-05-15T09:52:51.216Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-15T07:16:18.923

Modified: 2026-05-15T14:11:57.190

Link: CVE-2026-41702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-15T08:30:40Z