HIGH

CVE-2026-22719

Vmware Aria Operations 2026-02-25 CVSS v3.1
CVSS
8.1
KEV

Description

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. 

To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 

Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

Summary dbcve.org

VMware Aria Operations contains a command injection vulnerability allowing unauthenticated attackers to execute arbitrary commands during support-assisted product migration, leading to remote code execution (CVSS 8.1). The vulnerability is conditionally exploitable only while migration operations are in progress.

Mitigation

Apply vendor patches from VMSA-2026-0001 or implement documented workarounds from the response matrix. Since the vulnerability requires active migration to exploit, organizations should review migration status and prioritize patching of systems involved in or pending migration operations.

Patch Commit

Weakness (CWE)

CWE-77 Command Injection

EPSS Score

17.42%
Probability of exploitation in next 30 days
97th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE