>> All posts

CVE-2026-22720: VMware Aria Operations stored cross-site scripting, patch available

The short version: CVE-2026-22720 is a stored cross-site scripting (XSS) flaw in VMware Aria Operations. A user with privileges to create custom benchmarks can plant script that later runs in another user's browser session and performs administrative actions on their behalf. It requires an authenticated foothold and some user interaction, a patch is available, and there's no sign of exploitation. Address it on your normal patch cadence — steady, not urgent.

At a glance

FactDetail
Our severity takeModerate — in practice (see below)
CVSS v3.1 (NVD)8.0 — High · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS0.41% · 33.30th percentile (2026-07-17)
In CISA KEV?No — not listed
Known exploited?Not at time of writing
Vulnerability typeCWE-79 stored cross-site scripting → script execution / administrative actions in another user's session
Requires authenticated session?Yes — an account with privileges to create custom benchmarks, plus victim interaction
AffectedVMware Aria Operations 8.x (and bundled in VMware Cloud Foundation / Telco Cloud); see VMSA-2026-0001 for the full matrix
Fixed inPer VMSA-2026-0001: Aria Operations 8.18.6 and the other fixed builds in the Response Matrix

What you need to know

VMware Aria Operations (formerly vRealize Operations) is a monitoring and capacity-management platform for VMware environments. CVE-2026-22720 is a stored XSS: a user who can create custom benchmarks can save malicious script into the application, and when another user views the affected page, that script runs in their browser with their privileges — enough to perform administrative actions in Aria Operations.

The practical shape of the risk:

  • It's not pre-authentication. The attacker needs an account that can create custom benchmarks. This is an insider-or-foothold scenario, not an anonymous internet attack.
  • It needs a victim. As stored XSS, the payload fires when a legitimate user loads the page (UI:R in the vector) — so impact depends on who views it.
  • It's a privilege-escalation lever, not RCE. The prize is administrative actions inside Aria Operations, not code execution on the host. (The same advisory also covers CVE-2026-22721, a separate lower-severity privilege issue.)

How serious we see it

Moderate — below the 8.0 High band on paper, and here's the gap.

NVD's 8.0 reflects a serious confidentiality/integrity/availability impact if the stars align. Our real-world take is more measured because the preconditions are meaningful: the attacker already needs a privileged-enough account, a victim has to load the poisoned page, it isn't in CISA KEV, and EPSS is very low — there's no exploitation pressure. The reassuring part is straightforward: a vendor fix exists, the affected versions are enumerated, and this is a routine, plan-it patch rather than a drop-everything event.

Recommendations

Straight from Broadcom's advisory (VMSA-2026-0001):

  1. Patch on cadence. Upgrade Aria Operations to a fixed build (e.g. 8.18.6) per the Response Matrix; apply the corresponding Cloud Foundation / Telco Cloud fixes if bundled.
  2. Tighten who can create custom benchmarks. Limit that privilege to the users who genuinely need it — it's the precondition for this flaw.
  3. Keep the console off the public internet. Aria Operations is a management tool; restrict it to trusted networks.
  4. Confirm your exposure first. Verify whether you run an affected Aria Operations version at all.

How BreachRisk sees it

BreachRisk discovers internet-facing VMware Aria Operations panels in your external footprint and fingerprints the version, flagging exposure tied to this CVE. Because this flaw requires an authenticated, privileged foothold, our value here is mainly surfacing an Aria Operations console that's reachable when it shouldn't be — reducing the attack surface an insider or a stolen credential could use — rather than exploiting the XSS itself.

That outside-in view keeps management tooling honest: a monitoring console exposed to the internet is a finding worth closing, well before any specific bug is in play.

References

See your cyber risk, proven.