CVE-2023-20880: VMware Aria Operations

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

Affected products

  • VMware Aria Operations: from 8.6.0, before 8.12.0 (fixed in 8.12.0)
  • VMware Cloud Foundation: from 4.0, up to and including 4.5

Published 2023-05-12. Last modified 2026-06-17.