CVE-2026-22721: VMware Aria Operations privilege escalation vulnerability
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 .
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22721?
CVE-2026-22721 is considered a privilege escalation vulnerability that can allow unauthorized administrative access in VMware Aria Operations.
How do I fix CVE-2026-22721?
To remediate CVE-2026-22721, it is essential to apply the latest security patches provided by VMware for Aria Operations.
Who is affected by CVE-2026-22721?
CVE-2026-22721 affects users of VMware Aria Operations who have existing privileges in vCenter.
What are the risks of CVE-2026-22721?
The main risk of CVE-2026-22721 is that a malicious actor could leverage this vulnerability to gain unauthorized administrative access, compromising system security.
Is there a workaround for CVE-2026-22721 before applying a fix?
As of now, there are no documented workarounds for CVE-2026-22721, so timely patching is recommended.