CVE-2022-31656
Description
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authentication bypass in VMware Workspace ONE Access, Identity Manager, and vRealize Automation allows unauthenticated administrative access.
Vulnerability
VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. The bug allows a malicious actor with network access to the UI to obtain administrative access without needing to authenticate. The affected versions are those prior to the patches released in VMSA-2022-0021 [1].
Exploitation
An attacker needs only network access to the administrative UI of the affected product. No prior authentication or user interaction is required. By exploiting the authentication bypass, the attacker can gain administrative privileges directly.
Impact
Successful exploitation grants the attacker full administrative access to the affected system. This can lead to complete compromise of confidentiality, integrity, and availability of the application and potentially the underlying infrastructure.
Mitigation
VMware has released security updates to address this vulnerability as part of VMSA-2022-0021. Administrators should apply the relevant patches as soon as possible. No workarounds have been provided. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- VMware/Workspace ONE Access, Identity Manager and vRealize Automationdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.vmware.com/security/advisories/VMSA-2022-0021.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.