VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the Fixed Version column of the Response Matrix found inĀ VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 .
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Aria_operations | Vmware | 8.0 (including) | 8.18.6 (excluding) |
| Cloud_foundation | Vmware | 4.0 (including) | 5.2.3 (excluding) |
| Cloud_foundation | Vmware | 9.0 (including) | 9.0.2.0 (excluding) |
| Telco_cloud_infrastructure | Vmware | 2.2 (including) | 3.0 (including) |
| Telco_cloud_platform | Vmware | 4.0 (including) | 5.1 (including) |