CVE-2022-31702: VMware vRealize Network Insight

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.

Affected products

  • VMware vRealize Network Insight: version 6.2.0 only; version 6.3.0 only; version 6.4.0 only; version 6.5.1 only; version 6.6.0 only; version 6.7.0 only

Published 2022-12-14. Last modified 2026-06-17.