← Vulnerability feed

Vulnerability record · CVE-2021-22054 · published 17 December 2021

CVE-2021-22054: VMware Workspace ONE UEM console unauthenticated SSRF

Vmware · Workspace One Uem Console

The Workspace ONE UEM console contains a server-side request forgery flaw in versions 20.0.8 before 20.0.8.37, 20.11.0 before 20.11.0.40, 21.2.0 before 21.2.0.27, and 21.5.0 before 21.5.0.37. An attacker with network access can send crafted requests without authentication and reach sensitive information. It matters because the console is an internet-facing management plane and the flaw requires no credentials or user interaction.

7.5 CVSS 3.1 High CISA KEV since 9 Mar 2026 EPSS 100% · top 0.1% CWE-918 · Server-side request forgery (SSRF)
7.5CVSS 3.1 base score, v2 5.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw is unauthenticated, network-reachable, high confidentiality impact, listed in CISA KEV with a near-maximum EPSS score, and affects an internet-facing management console.

What it is

The Workspace ONE UEM console contains a server-side request forgery flaw in versions 20.0.8 before 20.0.8.37, 20.11.0 before 20.11.0.40, 21.2.0 before 21.2.0.27, and 21.5.0 before 21.5.0.37. An attacker with network access can send crafted requests without authentication and reach sensitive information. It matters because the console is an internet-facing management plane and the flaw requires no credentials or user interaction.

Impact

An attacker gains the ability to make the server issue requests on their behalf, exposing sensitive information reachable from the UEM console. The CVSS vector shows high confidentiality impact with no integrity or availability effect.

Attack surface

Reached over the network via the UEM console HTTP interface; the CVSS vector AV:N/PR:N/UI:N and the description confirm no authentication and no user interaction are required. Any host that can reach the console is a potential source.

Exploitation

CVE-2021-22054 is listed in CISA KEV with a due date of 2026-03-23, and EPSS shows a 30-day probability of 0.97369 (99.895th percentile), indicating active exploitation is expected or observed. A third-party advisory reference describes an SSRF exploitation surge.

What to do

  • Apply the vendor patch by upgrading to 20.0.8.37, 20.11.0.40, 21.2.0.27, or 21.5.0.37 as applicable per VMSA-2021-0029.
  • If patching cannot be completed immediately, restrict network access to the UEM console to trusted management networks and remove direct internet exposure.
  • Follow CISA KEV required action and BOD 22-01 guidance for cloud services, including discontinuing use if mitigations are unavailable.
  • Review and harden outbound egress filtering from the UEM console so it cannot reach internal metadata services or sensitive internal endpoints.
  • Monitor vendor advisory VMSA-2021-0029 for any updated guidance.

Detection

  • Inspect UEM console and reverse-proxy logs for requests containing absolute URLs, internal hostnames, or cloud metadata addresses (for example 169.254.169.254) in parameters.
  • Alert on outbound connections from the UEM console to internal RFC1918 ranges, loopback, or link-local addresses that are not part of normal operation.
  • Correlate unauthenticated requests to the UEM console with subsequent access to internal services or unusual response sizes.
  • Hunt for known SSRF payload patterns in HTTP request bodies and query strings against the UEM console endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-22054 to the Known Exploited Vulnerabilities catalog on 9 March 2026 as "Omnissa Workspace ONE Server-Side Request Forgery". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 March 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22054 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-22029Vmware workspace one uem console allocation without limits vulnerabilityVMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause…EPSS 0.96%10.0CVE-2026-83548SonicWall SMA1000 pre-auth SSRF via alternate access pathThe SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication.…KEVEPSS 8.8%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed9.3CVE-2026-64849MLflow unauthenticated webhook test endpoint SSRF via redirectMLflow before 3.15.0 validates the webhook URL only on the original request, while the delivery code follows redirects and re-resolves the hostname w…KEVEPSS 9.8%analysed10.0CVE-2026-15409SonicWall SMA1000 Work Place SSRF allows unauthenticated requestsThe SMA1000 Appliance Work Place interface contains a server-side request forgery flaw (CWE-918) that lets the appliance be induced to make requests …KEVEPSS 6.8%analysed8.6CVE-2026-20230Cisco Unified CM SSRF enables file write and root escalationCisco Unified Communications Manager and Unified CM SME fail to properly validate input for specific HTTP requests, allowing server-side request forg…KEVEPSS 88%analysed9.8CVE-2021-22175GitLab unauthenticated SSRF via internal webhook requestsGitLab is vulnerable to server-side request forgery when requests to the internal network for webhooks are enabled. The flaw affects all versions sta…KEVEPSS 53%analysed9.8CVE-2020-7796Zimbra Collaboration Suite WebEx zimlet SSRFZimbra Collaboration Suite before 8.8.15 Patch 7 is vulnerable to server-side request forgery when the WebEx zimlet is installed and its JSP is enabl…KEVEPSS 84%analysed

Source: NIST National Vulnerability Database (record CVE-2021-22054), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.