CVE-2023-20864: VMware Aria Operations For Logs

Critical severity, CVSS 9.8. EPSS: 70.4% chance of exploitation in the next 30 days.

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

Affected products

  • VMware Aria Operations For Logs: from 8.10.2, before 8.12.0 (fixed in 8.12.0)
  • VMware Cloud Foundation: from 4.0, up to and including 4.5

Published 2023-04-20. Last modified 2026-06-17.