High severity8.8NVD Advisory· Published Oct 31, 2023· Updated Jun 17, 2026
CVE-2023-20886
CVE-2023-20886
Description
VMware Workspace ONE UEM console contains an open redirect vulnerability.
A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user.
Affected products
2- cpe:2.3:a:vmware:workspace_one_uem:*:*:*:*:*:*:*:*Range: >=22.3.0.2,<22.3.0.48
Patches
Vulnerability mechanics
References
1- www.vmware.com/security/advisories/VMSA-2023-0025.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.