CVE-2022-22960

VMware Workspace ONE Access, Identity Manager and vRealize Automation

Published 13 Apr 2022 · updated 17 Jun 2026 · Analyzed

7.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 15 Apr 2022, with a remediation deadline of 6 May 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

References