PT-2026-21686 · Vmware · Vmware Aria Operations

Published

2026-02-24

·

Updated

2026-03-19

·

CVE-2026-22721

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware Aria Operations (affected versions not specified)
Description A malicious actor with privileges in vCenter to access VMware Aria Operations may leverage a privilege escalation issue to obtain administrative access in VMware Aria Operations. To remediate this issue, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMSA-2026-0001.
Recommendations Apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMSA-2026-0001.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02325
CVE-2026-22721

Affected Products

Vmware Aria Operations