To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// .
No analysis available yet.
Vendor Solution
Apply the vendor patches listed in the 'Fixed Version' column of the Response Matrix of VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 . Fixed versions include VMware Aria Operations 8.18.6 (for 8.x) and VMware Cloud Foundation Operations 9.0.2.0 (for 9.x).
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 04 Mar 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* |
Thu, 26 Feb 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware aria Operations Vmware cloud Foundation Vmware telco Cloud Infrastructure Vmware telco Cloud Platform |
|
| Vendors & Products |
Vmware
Vmware aria Operations Vmware cloud Foundation Vmware telco Cloud Infrastructure Vmware telco Cloud Platform |
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// . | |
| Title | VMware Aria Operations stored cross-site scripting vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-04-14T10:40:29.059Z
Reserved: 2026-01-09T06:54:36.841Z
Link: CVE-2026-22720
Updated: 2026-02-25T20:55:38.816Z
Status : Analyzed
Published: 2026-02-25T20:23:47.077
Modified: 2026-03-04T15:55:32.197
Link: CVE-2026-22720
No data.
OpenCVE Enrichment
Updated: 2026-02-26T13:14:56Z