Vulnerability record · CVE-2022-22954 · published 11 April 2022
CVE-2022-22954: VMware Workspace ONE Access and Identity Manager server-side template injection RCE
Vmware · Identity Manager
VMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-reachable attacker can inject template expressions that the server evaluates, leading to arbitrary command execution. Because the affected components are authentication and access-management infrastructure, compromise can expose identity and access control for the whole environment.
Description
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score, KEV listing with known ransomware use, and near-certain EPSS probability make this an urgent patch.
What it is
VMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-reachable attacker can inject template expressions that the server evaluates, leading to arbitrary command execution. Because the affected components are authentication and access-management infrastructure, compromise can expose identity and access control for the whole environment.
Impact
An unauthenticated attacker gains remote code execution on the affected appliance, allowing arbitrary commands, data theft, and further lateral movement into identity and management infrastructure. CISA notes known ransomware campaign use, so full host compromise is a realistic outcome.
Attack surface
Reachable over the network via the affected web interface; the CVSS vector shows no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N). No authentication is needed to trigger the injection.
Exploitation
CISA KEV lists it as exploited with known ransomware campaign use, and EPSS is near 1.0 (0.99997, 99.989th percentile). Public exploit code is referenced (Packet Storm), so exploitation is active and reliable.
What to do
- Apply the vendor updates in VMware advisory VMSA-2022-0011 immediately; this is the only complete fix.
- If patching cannot be done at once, remove internet exposure of Workspace ONE Access and Identity Manager and restrict access to trusted management networks.
- Audit the affected products (Workspace ONE Access, Identity Manager, vRealize Automation, Cloud Foundation, vRealize Suite Lifecycle Manager) and confirm which instances are reachable.
- Rotate credentials and secrets stored or managed by the affected appliances after patching, in case of prior compromise.
- Monitor for post-exploitation activity such as new admin accounts, unexpected outbound connections, and web shell or command execution artifacts.
Detection
- Search web and application logs for template-injection payloads (for example ${...} or similar expression syntax) in requests to the affected endpoints.
- Alert on unexpected child processes spawned by the Workspace ONE Access or Identity Manager service (for example shells, curl, wget, or scripting interpreters).
- Monitor for new or modified administrative accounts and authentication configuration changes on the appliances.
- Review network logs for outbound connections from the appliances to unfamiliar hosts, consistent with command-and-control or payload retrieval.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-22954 to the Known Exploited Vulnerabilities catalog on 14 April 2022 as "VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 5 May 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166935/VMware-Workspace-ONE-Access-Template-Injection-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2022-0011.html | Vendor Advisory |
| http://packetstormsecurity.com/files/166935/VMware-Workspace-ONE-Access-Template-Injection-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2022-0011.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22954 | US Government Resource |
Track CVE-2022-22954 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22954), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.