CVE-2026-22719 Details
Description
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
A command injection vulnerability has been identified in VMware Aria Operations. This vulnerability allows a malicious, unauthenticated actor to execute arbitrary commands, potentially leading to remote code execution, while support-assisted product migration is in progress. The issue is present in VMware Aria Operations versions 8.18.x prior to 8.18.6 and 9.0.x prior to 9.0.1.
To address this vulnerability, users can upgrade to VMware Aria Operations versions 8.18.6 or 9.0.2. For those using VMware Cloud Foundation, version 5.2.3 is available. Workaround instructions are also available for CVE-2026-22719.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22719 | CISA-ADP | US Government Resource |
| https://knowledge.broadcom.com/external/article/430349 | [email protected] | MitigationVendor Advisory |
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 | [email protected] | PatchVendor Advisory |
| https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations/8-18/vmware-aria-operations-8186-release-notes.html | [email protected] | Release Notes |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Broadcom VMware Aria Operations Command Injection Vulnerability | Mar 3, 2026 | Mar 24, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| vmware aria operations | >= 8.0, < 8.18.6 |
CPE
Remediation
| |
| vmware cloud foundation | >= 4.0, < 5.2.3 >= 9.0, < 9.0.2.0 |
CPE
Remediation
| |
| vmware telco cloud infrastructure | >= 2.2, <= 3.0 |
CPE
Remediation
| |
| vmware telco cloud platform | >= 4.0, <= 5.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2026 | Initial Analysis | [email protected] |
| Mar 3, 2026 | CVE Modified | CISA-ADP |
| Feb 26, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | New CVE Received | [email protected] |