CVE-2023-34063: VMware Aria Automation

High severity, CVSS 8.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.

Affected products

  • VMware Aria Automation: version 8.11.0 only; version 8.11.1 only; version 8.11.2 only; version 8.12.0 only; version 8.12.1 only; version 8.12.2 only; …
  • VMware Cloud Foundation: version 4.0 only; version 5.0 only

Published 2024-01-16. Last modified 2026-06-17.