CVE-2021-22054
Omnissa Workspace ONE Server-Side Request Forgery
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 23 March 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 97.37% probability · 100th percentile
- CISA KEV
- Listed 9 March 2026 · due 23 March 2026
- Weakness
- CWE-918
- Affected
- vmware/workspace one uem console
- Source
- security@vmware.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://web.archive.org/web/20211222154335/https://www.vmware.com/security/advisories/VMSA-2021-0029.html ; https://nvd.nist.gov/vuln/detail/CVE-2021-22054
References
- https://www.vmware.com/security/advisories/VMSA-2021-0029.htmlPatch, Vendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2021-0029.htmlPatch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22054US Government Resource
- https://www.greynoise.io/blog/new-ssrf-exploitation-surgeThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.