S4E just found a low-severity finding from missing http security headers implementation scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-22956

9.8
CVSS
Description

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

Attack Vector
-
Privileges Req.
-
User Interaction
-
vmware workspace one access
Updated Sep 28, 2026View on NVD →
S4E scanner

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →