Privilege Escalation Vulnerability in VMware Aria Operations
CVE-2026-22721
6.2MEDIUM
Key Information:
- Vendor
Vmware
- Status
- Vendor
- CVE Published:
- 25 February 2026
What is CVE-2026-22721?
VMware Aria Operations is affected by a privilege escalation vulnerability that allows a threat actor with existing privileges in vCenter to gain unauthorized administrative access. This exploitation can lead to heightened permissions within the application, potentially allowing malicious activities. To mitigate this risk, users are advised to apply the patches provided in the Response Matrix documented in VMSA-2026-0001 and review the release notes for resolution details. Regularly updating your systems is crucial in maintaining security against such vulnerabilities.
Affected Version(s)
VMware Aria Operations 8.18.0
VMware Aria Operations 8.18.0 < 8.18.6
VMware Cloud Foundation 4.0