Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-22719

Опубликовано: 25 фев. 2026
Источник: nvd
CVSS3: 8.1
EPSS Средний

Описание

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. 

To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 

Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
Версия от 8.0 (включая) до 8.18.6 (исключая)
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 5.2.3 (исключая)
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
Версия от 9.0 (включая) до 9.0.2.0 (исключая)
cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
Версия от 2.2 (включая) до 3.0 (включая)
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 5.1 (включая)

EPSS

Процентиль: 97%
0.17424
Средний

8.1 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.1
github
5 месяцев назад

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

CVSS3: 8.1
fstec
5 месяцев назад

Уязвимость инструмента мониторинга виртуальной инфраструктуры VMware Aria Operations, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.17424
Средний

8.1 High

CVSS3

Дефекты

CWE-77