Privilege Escalation Vulnerability in VMware Aria Operations
CVE-2026-22721

6.2MEDIUM

What is CVE-2026-22721?

VMware Aria Operations is affected by a privilege escalation vulnerability that allows a threat actor with existing privileges in vCenter to gain unauthorized administrative access. This exploitation can lead to heightened permissions within the application, potentially allowing malicious activities. To mitigate this risk, users are advised to apply the patches provided in the Response Matrix documented in VMSA-2026-0001 and review the release notes for resolution details. Regularly updating your systems is crucial in maintaining security against such vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

VMware Aria Operations 8.18.0

VMware Aria Operations 8.18.0 < 8.18.6

VMware Cloud Foundation 4.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.