CVE-2023-20865: VMware Aria Operations For Logs
High severity, CVSS 7.2. EPSS: 1.6% chance of exploitation in the next 30 days.
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
Affected products
- VMware Aria Operations For Logs: from 8.6.0, before 8.12.0 (fixed in 8.12.0)
- VMware Cloud Foundation: from 4.0, up to and including 4.5
Published 2023-04-20. Last modified 2026-06-17.