CVE-2026-22719: Broadcom VMware Aria Operations Command Injection Vulnerability
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22719?
CVE-2026-22719 is considered a critical command injection vulnerability that may lead to remote code execution.
How do I fix CVE-2026-22719?
To fix CVE-2026-22719, update VMware Aria Operations to the latest version provided by VMware.
Who is affected by CVE-2026-22719?
CVE-2026-22719 affects all versions of VMware Aria Operations prior to the patched releases.
Can CVE-2026-22719 be exploited remotely?
Yes, CVE-2026-22719 can be exploited by a malicious unauthenticated actor remotely.
What can happen if CVE-2026-22719 is exploited?
Exploitation of CVE-2026-22719 can result in the execution of arbitrary commands, potentially leading to full system compromise.