Vulnerability record · CVE-2021-22054 · published 17 December 2021
CVE-2021-22054: VMware Workspace ONE UEM console unauthenticated SSRF
Vmware · Workspace One Uem Console
The Workspace ONE UEM console contains a server-side request forgery flaw in versions 20.0.8 before 20.0.8.37, 20.11.0 before 20.11.0.40, 21.2.0 before 21.2.0.27, and 21.5.0 before 21.5.0.37. An attacker with network access can send crafted requests without authentication and reach sensitive information. It matters because the console is an internet-facing management plane and the flaw requires no credentials or user interaction.
Description
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is unauthenticated, network-reachable, high confidentiality impact, listed in CISA KEV with a near-maximum EPSS score, and affects an internet-facing management console.
What it is
The Workspace ONE UEM console contains a server-side request forgery flaw in versions 20.0.8 before 20.0.8.37, 20.11.0 before 20.11.0.40, 21.2.0 before 21.2.0.27, and 21.5.0 before 21.5.0.37. An attacker with network access can send crafted requests without authentication and reach sensitive information. It matters because the console is an internet-facing management plane and the flaw requires no credentials or user interaction.
Impact
An attacker gains the ability to make the server issue requests on their behalf, exposing sensitive information reachable from the UEM console. The CVSS vector shows high confidentiality impact with no integrity or availability effect.
Attack surface
Reached over the network via the UEM console HTTP interface; the CVSS vector AV:N/PR:N/UI:N and the description confirm no authentication and no user interaction are required. Any host that can reach the console is a potential source.
Exploitation
CVE-2021-22054 is listed in CISA KEV with a due date of 2026-03-23, and EPSS shows a 30-day probability of 0.97369 (99.895th percentile), indicating active exploitation is expected or observed. A third-party advisory reference describes an SSRF exploitation surge.
What to do
- Apply the vendor patch by upgrading to 20.0.8.37, 20.11.0.40, 21.2.0.27, or 21.5.0.37 as applicable per VMSA-2021-0029.
- If patching cannot be completed immediately, restrict network access to the UEM console to trusted management networks and remove direct internet exposure.
- Follow CISA KEV required action and BOD 22-01 guidance for cloud services, including discontinuing use if mitigations are unavailable.
- Review and harden outbound egress filtering from the UEM console so it cannot reach internal metadata services or sensitive internal endpoints.
- Monitor vendor advisory VMSA-2021-0029 for any updated guidance.
Detection
- Inspect UEM console and reverse-proxy logs for requests containing absolute URLs, internal hostnames, or cloud metadata addresses (for example 169.254.169.254) in parameters.
- Alert on outbound connections from the UEM console to internal RFC1918 ranges, loopback, or link-local addresses that are not part of normal operation.
- Correlate unauthenticated requests to the UEM console with subsequent access to internal services or unusual response sizes.
- Hunt for known SSRF payload patterns in HTTP request bodies and query strings against the UEM console endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-22054 to the Known Exploited Vulnerabilities catalog on 9 March 2026 as "Omnissa Workspace ONE Server-Side Request Forgery". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.vmware.com/security/advisories/VMSA-2021-0029.html | PatchVendor Advisory |
| https://www.vmware.com/security/advisories/VMSA-2021-0029.html | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22054 | US Government Resource |
| https://www.greynoise.io/blog/new-ssrf-exploitation-surge | Third Party Advisory |
Track CVE-2021-22054 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22054), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.