Database/Control plane, storage & DevOps
VMware Aria Operations (command injection during assisted migration): An unauthenticated attacker injects commands
Impact
An unauthenticated attacker injects commands and reaches remote code execution on Aria Operations while a support-assisted product migration is running. The exposure window is operational rather than permanent - it opens exactly when you are mid-migration and least able to respond.
Who can reach it
Unauthenticated network access during a support-assisted migration window.
What to do
Apply the patches in Broadcom advisory 36947 before undertaking any assisted migration. If a migration is already in flight, restrict network access to the Aria Operations appliance for its duration.
References
Related entries
- OpenStack glance_store: VMware datastore driver sends authentication headers to an attacker-supplied image location hostCVE-2026-51773 · OpenStack glance_store (VMware datastore driver, _retry_request)High
- Ceph RGW: unsigned x-amz-* headers on presigned URLs are honored, letting a URL holder escalate privilegesCVE-2026-54330 · Ceph Object Gateway (RGW SigV4 presigned-URL header validation)High
- Apache Airflow Git provider: SSH host-key verification disabled by default when cloning DAG bundlesCVE-2026-58065 · Apache Airflow Git provider (apache-airflow-providers-git, git-over-SSH host key checking)High
- Apache Airflow FAB provider: a DAG named 'DAGs' collides with the global all-DAGs permission and escalates privilegesCVE-2026-59245 · Apache Airflow FAB auth manager (apache-airflow-providers-fab, resource_name collision)High
- Linux MACsec (replay protection at XPN lower-PN wrap): MACsec replay protection fails at the extended-packet-numberCVE-2026-63925 · Linux MACsec (replay protection at XPN lower-PN wrap)High
- Atlantis: workspace names escape the working directory into os.RemoveAll and os.MkdirAllCVE-2026-64679 · Atlantis (workspace path handling in atlantis.yaml and /api/plan)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.