CVE-2026-22719
Vulnerability Summary
Timeline
Description
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 2.07%• Percentile: 84%
Techniques & Countermeasures
- CWE-77•Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Affected Systems
- vmware•aria_operations
≥ 8.18.0, < 8.18.6 | ≥ 8.0, < 8.18.6
- vmware•cloud_foundation
≥ 4.0, < 5.2.3 | ≥ 9.0, < 9.0.2.0
- vmware•cloud foundationcust
≥ 9.0, < 9.0.2 | ≥ 4.0, < 5.2.3
- vmware•telco_cloud_infrastructure
≥ 2.0, < 5.2.3 | ≥ 2.2, ≤ 3.0
- vmware•telco_cloud_platform
≥ 2.0, < 5.2.3 | ≥ 4.0, ≤ 5.1
References (4)
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947
- https://knowledge.broadcom.com/external/article/430349
- https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations/8-18/vmware-aria-operations-8186-release-notes.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22719