CVE-2026-22720

CRITICAL WAF: High
CVSS 9.0 Published: 2026-02-25
CWE-79

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.  To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// .

WAF Coverage Analysis

Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE

Affected Software

VendorProductVersion
vmwarearia_operations8.0 - 8.18.6
vmwarecloud_foundation4.0 - 5.2.3
vmwarecloud_foundation9.0 - 9.0.2.0
vmwaretelco_cloud_infrastructure2.2 - 3.0
vmwaretelco_cloud_platform4.0 - 5.1

References

Back to CVE Database