CVE-2026-22719: Broadcom VMware Aria Operations Command Injection Vulnerability
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
Other sources
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.
To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VMware Aria Operationsto a version that resolves this vulnerability.Fixed in 8.18.6 - Upgrade
Upgrade
VMware Cloud Foundation Operationsto a version that resolves this vulnerability.Fixed in 9.0.2.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch VMSA-2026-0001 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22719?
CVE-2026-22719 is considered a critical command injection vulnerability that may lead to remote code execution.
How do I fix CVE-2026-22719?
To fix CVE-2026-22719, update VMware Aria Operations to the latest version provided by VMware.
Who is affected by CVE-2026-22719?
CVE-2026-22719 affects all versions of VMware Aria Operations prior to the patched releases.
Can CVE-2026-22719 be exploited remotely?
Yes, CVE-2026-22719 can be exploited by a malicious unauthenticated actor remotely.
What can happen if CVE-2026-22719 is exploited?
Exploitation of CVE-2026-22719 can result in the execution of arbitrary commands, potentially leading to full system compromise.