CVE-2023-20858: VMware Carbon Black App Control

High severity, CVSS 7.2. EPSS: 16.9% chance of exploitation in the next 30 days.

VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted input allowing access to the underlying server operating system.

Affected products

  • VMware Carbon Black App Control: from 8.7.0, before 8.7.8 (fixed in 8.7.8); from 8.8.0, before 8.8.6 (fixed in 8.8.6); from 8.9.0, before 8.9.4 (fixed in 8.9.4)

Published 2023-02-22. Last modified 2026-06-17.