CVE-2026-22720: VMware Aria Operations stored cross-site scripting vulnerability
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.
To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// .
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22720?
CVE-2026-22720 is classified as a stored cross-site scripting vulnerability that can lead to unauthorized administrative actions.
How do I fix CVE-2026-22720?
To fix CVE-2026-22720, upgrade to the latest version of VMware Aria Operations that addresses this vulnerability.
Who is affected by CVE-2026-22720?
Any user with privileges to create custom benchmarks in VMware Aria Operations is potentially affected by CVE-2026-22720.
What could an attacker do with CVE-2026-22720?
An attacker with access can inject malicious scripts that may perform unauthorized actions within VMware Aria Operations.
Is CVE-2026-22720 a critical vulnerability?
While CVE-2026-22720 is serious due to its potential for exploitation, its criticality depends on the specific context of the affected systems.