← back
CVE-2022-22956observed exploitation

CVE-2022-22956

52Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 51%
from disclosure to weapon0 days
Published on NVDApr 13
metasploitApr 6
VulnCheck+1239d
exploitation probability
51%top 1% of all CVEs
observed exploitation
yesVulnCheck
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.