← Vulnerability feed

Vulnerability record · CVE-2022-22956 · published 13 April 2022

CVE-2022-22956: VMware Workspace ONE Access OAuth2 authentication bypass

Vmware · Identity Manager

VMware Workspace ONE Access (and related Identity Manager and vRealize Automation deployments) contains an authentication bypass in the OAuth2 ACS framework, tracked alongside CVE-2022-22955. Exposed endpoints in the authentication framework let an actor skip authentication entirely, which matters because this component is the identity gateway for downstream enterprise applications.

9.8 CVSS 3.1 Critical EPSS 50% · top 1.1% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no privileges or user interaction required, an authentication bypass in an identity gateway, and a very high EPSS score make this an urgent patch target.

What it is

VMware Workspace ONE Access (and related Identity Manager and vRealize Automation deployments) contains an authentication bypass in the OAuth2 ACS framework, tracked alongside CVE-2022-22955. Exposed endpoints in the authentication framework let an actor skip authentication entirely, which matters because this component is the identity gateway for downstream enterprise applications.

Impact

An unauthenticated attacker can bypass authentication and execute arbitrary operations within the affected service, with CVSS 3.1 scoring confidentiality, integrity and availability all High. In an identity product this can mean forging or hijacking sessions and reaching systems that trust it.

Attack surface

Reached over the network via the exposed OAuth2 ACS endpoints; the CVSS vector shows no privileges required and no user interaction, so no valid credentials are needed. The description does not specify which exact endpoint or request sequence is abused.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.498 (98.8th percentile) and public Packet Storm exploit write-ups exist, so exploitation is plausible and should be treated as likely. The record does not confirm in-the-wild attacks.

What to do

  • Apply the vendor patch per VMware advisory VMSA-2022-0011 for Workspace ONE Access, Identity Manager and vRealize Automation.
  • If patching cannot be immediate, restrict network access to the OAuth2 ACS and authentication endpoints to trusted sources only.
  • Rotate credentials, session tokens and any secrets that may have been exposed through the affected authentication service.
  • Review identity provider and SSO logs for anomalous token issuance or authentication events during the exposure window.

Detection

  • Hunt for authentication or token-issuance events on Workspace ONE Access that lack a preceding valid login or come from unexpected source IPs.
  • Monitor requests to OAuth2 ACS endpoints for unusual parameters, malformed assertions or repeated failures followed by success.
  • Alert on new administrative accounts, role changes or configuration modifications in Workspace ONE Access outside change windows.
  • Correlate downstream application access with the identity provider to spot sessions that were never legitimately authenticated.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22956 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22954VMware Workspace ONE Access and Identity Manager server-side template injection RCEVMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-r…KEVEPSS 100%analysed9.1CVE-2020-4006VMware Workspace ONE Access and Identity Manager command injectionVMware Workspace ONE Access, Access Connector, Identity Manager, and Identity Manager Connector contain an OS command injection flaw (CWE-78). A remo…KEVEPSS 17%analysed7.8CVE-2022-22960VMware Workspace ONE Access and related products local privilege escalationVMware Workspace ONE Access, Identity Manager, vRealize Automation and related products ship support scripts with incorrect permission assignments (C…KEVEPSS 36%analysed9.8CVE-2022-31656Vmware identity manager vulnerabilityVMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A …EPSS 23%9.8CVE-2022-31657Vmware identity manager open redirect vulnerabilityVMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect…EPSS 1.3%9.8CVE-2022-22972VMware Workspace ONE Access and related products authentication bypassVMware Workspace ONE Access, Identity Manager, and vRealize Automation contain an authentication bypass affecting local domain users. A remote attack…EPSS 56%analysed9.8CVE-2022-22955Vmware identity manager vulnerabilityVMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious …EPSS 7.9%9.8CVE-2021-22002Vmware identity manager improper authentication vulnerabilityVMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2022-22956), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.