CVE-2022-22972: VMware Cloud Foundation

Critical severity, CVSS 9.8. EPSS: 56.3% chance of exploitation in the next 30 days.

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

Affected products

  • VMware Cloud Foundation: version 3.0 only; version 3.0.1 only; version 3.0.1.1 only; version 3.5 only; version 3.5.1 only; version 3.7 only; …
  • VMware Identity Manager: version 3.3.3 only; version 3.3.4 only; version 3.3.5 only; version 3.3.6 only
  • VMware vRealize Automation: version 7.6 only
  • VMware vRealize Suite Lifecycle Manager: version 8.0 only; version 8.0.1 only; version 8.1 only; version 8.2 only; version 8.3 only; version 8.4 only; …
  • VMware Workspace One Access: version 20.10.0.0 only; version 20.10.0.1 only; version 21.08.0.0 only; version 21.08.0.1 only

Published 2022-05-20. Last modified 2026-06-17.