S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 15, 2025

CVE-2022-22956 Scanner

CVE-2022-22956 Scanner - Authentication Bypass vulnerability in VMware Workspace ONE Access

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-22956
9.8
CVSS

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
VMware Workspace ONE Accessby n/a
Access 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0.
Updated Aug 22, 2026View on NVD →
Detail

VMware Workspace ONE Access is used by organizations worldwide for secure identity and access management. It allows employees to access enterprise applications and data from anywhere, enhancing work flexibility and productivity. Companies use it to ensure secure authentication and authorization processes for their digital resources. The software integrates with various identity providers and entitles users to access needed applications through a single login interface. It benefits enterprises by minimizing the footprint of unauthorized access and streamlining identity management processes. The solution is commonly used in industries with stringent security and compliance requirements, such as finance, healthcare, and government sectors.

The Authentication Bypass vulnerability in VMware Workspace ONE Access allows attackers to circumvent security controls. It exploits gaps in the OAuth2 ACS framework, leading to unauthorized privileges. Malicious entities can potentially access account details and sensitive data without proper authentication. This vulnerability can be detrimental, as bypassing authentication can lead to unauthorized access to critical systems and data breaches. The exploitation requires no user interaction, increasing the risk for organizations using affected versions. Due to its serious implications, this has been classified under critical security issues.

The vulnerability resides in the OAuth2 framework's exposed endpoints, which can be manipulated for unauthorized access. Attackers use the /SAAS/API/1.0/REST/oauth2 endpoints to generate activation tokens without restriction. They exploit the token generation process to align with legitimate authentication sessions, bypassing the need for credential verification. Upon gaining "client_id" and "client_secret," attackers can forge valid session tokens. The attack is accomplished by carefully constructing POST requests with the necessary parameters. The security flaw is significant due to its potential for enabling remote threats without needing direct access.

Exploiting this vulnerability risks compromising complete access control measures and sensitive data integrity. Attackers can execute operations typically restricted to authenticated users. System manipulation can follow, including altering configurations or deploying malicious software. Exposure to this flaw could lead to unauthorized data dumps or lateral movement across other networked systems. Organizations often face legal non-compliance risks post-breach, financial setbacks, and reputational damage. Heightened threat levels necessitate a swift response in applying necessary security mitigations.

REFERENCES

Solution Advice
  • Upgrade to the latest version of VMware Workspace ONE Access where the vulnerabilities have been patched.
  • Regularly monitor access logs for unusual login activities or failed authentication attempts.
  • Implement multi-factor authentication (MFA) to add an additional security layer.
  • Review firewall settings and limit access to the vulnerable services to only necessary IP ranges.
  • Conduct security training for users to recognize and report suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.