VYPR
Unrated severityNVD Advisory· Published Feb 25, 2026· Updated Apr 14, 2026

VMware Aria Operations stored cross-site scripting vulnerability

CVE-2026-22720

Description

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.

To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// .

Affected products

5
  • VMware/VMware Aria Operationsv5
    Range: 8.18.0
  • VMware/VMware Cloud Foundation Operationsv5
    Range: 4.x
  • VMware/VMware Telco Cloud Infrastructurev5
    Range: 2.0
  • VMware/VMware Telco Cloud Platformv5
    Range: 4.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.