Skip to content

Conversation

@daffainfo
Copy link
Contributor

Template / PR Information

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

Template Validation

I've validated this template locally?

  • YES
  • NO

Updated CVE-2022-22956.yaml with additional impact, remediation, and metadata details.
@DhiyaneshGeek DhiyaneshGeek merged commit a1f9350 into projectdiscovery:main Oct 15, 2025
3 checks passed
@algora-pbc
Copy link

algora-pbc bot commented Oct 21, 2025

🎉🎈 @daffainfo has been awarded $200 by ProjectDiscovery! 🎈🎊

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants