PT-2026-21686 · Vmware · Vmware Aria Operations
Published
2026-02-24
·
Updated
2026-03-19
·
CVE-2026-22721
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VMware Aria Operations (affected versions not specified)
Description
A malicious actor with privileges in vCenter to access VMware Aria Operations may leverage a privilege escalation issue to obtain administrative access in VMware Aria Operations. To remediate this issue, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMSA-2026-0001.
Recommendations
Apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMSA-2026-0001.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Aria Operations