CVE-2026-22719

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*

History

04 Mar 2026, 15:08

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
First Time Vmware cloud Foundation
Vmware telco Cloud Platform
Vmware telco Cloud Infrastructure
Vmware
Vmware aria Operations
References () https://knowledge.broadcom.com/external/article/430349 - () https://knowledge.broadcom.com/external/article/430349 - Mitigation, Vendor Advisory
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 - Patch, Vendor Advisory
References () https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations/8-18/vmware-aria-operations-8186-release-notes.html - () https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations/8-18/vmware-aria-operations-8186-release-notes.html - Release Notes
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22719 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22719 - US Government Resource

03 Mar 2026, 20:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22719 -

26 Feb 2026, 16:24

Type Values Removed Values Added
CWE CWE-77

25 Feb 2026, 20:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 20:23

Updated : 2026-03-04 15:08


NVD link : CVE-2026-22719

Mitre link : CVE-2026-22719

CVE.ORG link : CVE-2026-22719


JSON object : View

Products Affected

vmware

  • aria_operations
  • telco_cloud_platform
  • cloud_foundation
  • telco_cloud_infrastructure
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')