CVE-2026-22720
8.0VMware · Aria Operations
VMware Aria Operations contains a stored cross-site scripting (XSS) vulnerability that allows authenticated attackers to perform administrative actions.
Executive summary
An authenticated stored cross-site scripting vulnerability in VMware Aria Operations allows attackers with custom benchmark creation privileges to execute unauthorized administrative actions.
Vulnerability
This is a stored cross-site scripting vulnerability (CWE-79) triggered when an attacker with existing privileges to create custom benchmarks injects malicious scripts into the application. The vulnerability requires the attacker to be authenticated with specific low-level privileges to interact with the benchmark creation feature.
Business impact
The potential for unauthorized administrative actions poses a significant risk to the integrity and confidentiality of the Aria Operations environment. With a CVSS score of 8.0, this high-severity vulnerability could allow a compromised account to escalate its influence, potentially leading to full administrative takeover of the platform, unauthorized data access, or disruption of critical monitoring services.
Remediation
Immediate Action: Apply the vendor-supplied patches as detailed in the VMSA-2026-0001 security advisory, specifically updating to version 8.18.6 or newer for Aria Operations.
Proactive Monitoring: Review administrative audit logs for suspicious activity related to custom benchmark creation or unexpected changes to system configurations.
Compensating Controls: Implement strict role-based access control (RBAC) to limit the number of users with permission to create custom benchmarks until patching is completed.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the high CVSS score and the potential for administrative privilege escalation, organizations should prioritize the installation of the provided vendor patches. Ensure that user access rights are reviewed and restricted to only those individuals who require the ability to create benchmarks to minimize the risk of internal exploitation.