← Vulnerability feed

Vulnerability record · CVE-2022-22954 · published 11 April 2022

CVE-2022-22954: VMware Workspace ONE Access and Identity Manager server-side template injection RCE

Vmware · Identity Manager

VMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-reachable attacker can inject template expressions that the server evaluates, leading to arbitrary command execution. Because the affected components are authentication and access-management infrastructure, compromise can expose identity and access control for the whole environment.

9.8 CVSS 3.1 Critical CISA KEV since 14 Apr 2022 Known ransomware use EPSS 100% · top 0.1% CWE-94 · Code injection
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score, KEV listing with known ransomware use, and near-certain EPSS probability make this an urgent patch.

What it is

VMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-reachable attacker can inject template expressions that the server evaluates, leading to arbitrary command execution. Because the affected components are authentication and access-management infrastructure, compromise can expose identity and access control for the whole environment.

Impact

An unauthenticated attacker gains remote code execution on the affected appliance, allowing arbitrary commands, data theft, and further lateral movement into identity and management infrastructure. CISA notes known ransomware campaign use, so full host compromise is a realistic outcome.

Attack surface

Reachable over the network via the affected web interface; the CVSS vector shows no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N). No authentication is needed to trigger the injection.

Exploitation

CISA KEV lists it as exploited with known ransomware campaign use, and EPSS is near 1.0 (0.99997, 99.989th percentile). Public exploit code is referenced (Packet Storm), so exploitation is active and reliable.

What to do

  • Apply the vendor updates in VMware advisory VMSA-2022-0011 immediately; this is the only complete fix.
  • If patching cannot be done at once, remove internet exposure of Workspace ONE Access and Identity Manager and restrict access to trusted management networks.
  • Audit the affected products (Workspace ONE Access, Identity Manager, vRealize Automation, Cloud Foundation, vRealize Suite Lifecycle Manager) and confirm which instances are reachable.
  • Rotate credentials and secrets stored or managed by the affected appliances after patching, in case of prior compromise.
  • Monitor for post-exploitation activity such as new admin accounts, unexpected outbound connections, and web shell or command execution artifacts.

Detection

  • Search web and application logs for template-injection payloads (for example ${...} or similar expression syntax) in requests to the affected endpoints.
  • Alert on unexpected child processes spawned by the Workspace ONE Access or Identity Manager service (for example shells, curl, wget, or scripting interpreters).
  • Monitor for new or modified administrative accounts and authentication configuration changes on the appliances.
  • Review network logs for outbound connections from the appliances to unfamiliar hosts, consistent with command-and-control or payload retrieval.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-22954 to the Known Exploited Vulnerabilities catalog on 14 April 2022 as "VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 5 May 2022.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22954 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-38812VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its DCERPC protocol implementation. A remote, unauthenticated attacker can …KEVEPSS 55%analysed9.8CVE-2024-37079VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-overflow (out-of-bounds write) in its DCERPC protocol implementation. A remote, unauthenticated attacker can send a cr…KEVEPSS 22%analysed9.8CVE-2021-22005VMware vCenter Server Analytics arbitrary file upload to RCEThe Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-2…KEVEPSS 100%analysed9.8CVE-2021-21985VMware vCenter Server Virtual SAN Health Check plug-in RCEThe vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allow…KEVEPSS 100%analysed9.8CVE-2021-21972VMware vCenter Server plugin path traversal leads to remote code executionThe vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to u…KEVEPSS 100%analysed9.8CVE-2020-3992VMware ESXi OpenSLP use-after-free allows remote code executionOpenSLP as used in VMware ESXi contains a use-after-free flaw reachable over port 427 on the management network. An unauthenticated attacker with net…KEVEPSS 83%analysed9.1CVE-2020-4006VMware Workspace ONE Access and Identity Manager command injectionVMware Workspace ONE Access, Access Connector, Identity Manager, and Identity Manager Connector contain an OS command injection flaw (CWE-78). A remo…KEVEPSS 17%analysed

Source: NIST National Vulnerability Database (record CVE-2022-22954), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.