CVE-2022-22954

CRITICAL KEV RANSOMWARE NUCLEI

VMware Workspace ONE Access CVE-2022-22954

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2022-22954 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added April 14, 2022, with confirmed use in ransomware campaigns. EIP tracks 28 public exploits from researchers including Schira4396, sherlocksecurity, bewhale, including a Metasploit module exploits/linux/http/vmware_workspace_one_access_cve_2022_22954. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a Go-based exploit tool for multiple VMware vCenter vulnerabilities, including CVE-2022-22954 (RCE), CVE-2021-21972, CVE-2021-21985, CVE-2021-22005, and Log4j (CVE-2021-44228). It supports command execution, file upload, reverse shells, and SSH key deployment.

Description

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

Exploits (28)

nomisec WORKING POC 1,464 stars
by Schira4396 · remote
https://github.com/Schira4396/VcenterKiller

This repository contains a Go-based exploit tool for multiple VMware vCenter vulnerabilities, including CVE-2022-22954 (RCE), CVE-2021-21972, CVE-2021-21985, CVE-2021-22005, and Log4j (CVE-2021-44228). It supports command execution, file upload, reverse shells, and SSH key deployment.

Classification
Working Poc 95%
Attack Type
Rce | Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: VMware vCenter (multiple versions)
No auth needed
Prerequisites: Network access to target vCenter instance · Vulnerable vCenter version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 282 stars
by sherlocksecurity · remote
https://github.com/sherlocksecurity/VMware-CVE-2022-22954

This PoC demonstrates a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access, allowing arbitrary command execution via a crafted GET request. The payload executes `cat /etc/passwd` as proof of concept.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware Workspace ONE Access (versions affected by CVE-2022-22954)
No auth needed
Prerequisites: Network access to the vulnerable VMware Workspace ONE Access instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 70 stars
by bewhale · poc
https://github.com/bewhale/CVE-2022-22954

This repository contains a Python-based exploit for CVE-2022-22954, a FreeMarker template injection vulnerability in VMware Workspace ONE Access. The exploit supports command execution, file writing, and batch scanning across multiple endpoints.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access (versions affected by CVE-2022-22954)
No auth needed
Prerequisites: Network access to the target VMware Workspace ONE Access instance · Vulnerable endpoint exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 16 stars
by tunelko · remote
https://github.com/tunelko/CVE-2022-22954-PoC

This PoC exploits CVE-2022-22954, a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access and Identity Manager. It allows remote command execution by injecting a Freemarker template payload via the `deviceUdid` parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access and Identity Manager
No auth needed
Prerequisites: Target must be running a vulnerable version of VMware Workspace ONE Access/Identity Manager · Network access to the target's `/catalog-portal/ui/oauth/verify` endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 12 stars
by jax7sec · remote
https://github.com/jax7sec/CVE-2022-22954

This repository contains a functional proof-of-concept exploit for CVE-2022-22954, a template injection vulnerability in VMware Workspace ONE Access. The exploit leverages Freemarker template utility to execute arbitrary commands via a crafted URI, with support for both scanning and RCE modes.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware Workspace ONE Access
No auth needed
Prerequisites: Network access to the target Workspace ONE Access instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 11 stars
by Vulnmachines · poc
https://github.com/Vulnmachines/VMWare_CVE-2022-22954

This repository contains a writeup and images describing CVE-2022-22954, a server-side template injection vulnerability in VMware Workspace ONE Access and Identity Manager. No exploit code is provided, only references and social media links.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: VMware Workspace ONE Access and Identity Manager
No auth needed
Prerequisites: Access to vulnerable VMware instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 10 stars
by DrorDvash · remote
https://github.com/DrorDvash/CVE-2022-22954_VMware_PoC

This PoC exploits a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access via Freemarker template manipulation. It constructs a malicious payload to execute arbitrary commands (e.g., 'cat /etc/passwd') by abusing the 'freemarker.template.utility.Execute' class.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware Workspace ONE Access and Identity Manager (versions affected by CVE-2022-22954)
No auth needed
Prerequisites: Network access to the target VMware Workspace ONE Access instance · The target must be vulnerable to CVE-2022-22954
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 8 stars
by orwagodfather · remote
https://github.com/orwagodfather/CVE-2022-22954

This repository contains a Python-based PoC for CVE-2022-22954, a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access. The exploit allows remote command execution by injecting malicious payloads into the deviceUdid parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access and Identity Manager
No auth needed
Prerequisites: Network access to the vulnerable VMware Workspace ONE Access instance · Python environment with required libraries (requests, shodan, etc.)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 4 stars
by b4dboy17 · poc
https://github.com/b4dboy17/CVE-2022-22954

This repository contains a Python-based PoC for CVE-2022-22954, a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access. The exploit allows remote command execution by injecting payloads into the deviceUdid parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access and Identity Manager
No auth needed
Prerequisites: Target must be running a vulnerable version of VMware Workspace ONE Access · Network access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 4 stars
by aniqfakhrul · poc
https://github.com/aniqfakhrul/CVE-2022-22954

This PoC exploits CVE-2022-22954, a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access. It allows remote command execution by injecting Freemarker template expressions via the `deviceUdid` parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware Workspace ONE Access (versions affected by CVE-2022-22954)
No auth needed
Prerequisites: Network access to the target · Vulnerable endpoint exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 4 stars
by MLX15 · poc
https://github.com/MLX15/CVE-2022-22954

This is a functional exploit PoC for CVE-2022-22954, targeting VMware Workspace ONE Access. It leverages a FreeMarker template injection vulnerability to achieve remote code execution (RCE) and file writing capabilities.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access
No auth needed
Prerequisites: Network access to the target VMware Workspace ONE Access instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by Chocapikk · poc
https://github.com/Chocapikk/CVE-2022-22954

This repository contains a Python-based PoC for CVE-2022-22954, a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access and Identity Manager. The exploit allows remote command execution by sending a crafted payload to the vulnerable endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access and Identity Manager
No auth needed
Prerequisites: Target must be running a vulnerable version of VMware Workspace ONE Access or Identity Manager · Network access to the target's vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by axingde · poc
https://github.com/axingde/CVE-2022-22954-POC

This repository contains a Python-based proof-of-concept (PoC) for CVE-2022-22954, a vulnerability in VMware. The script checks for the presence of the vulnerability by sending a crafted HTTP request to the target URL and analyzing the response.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware
No auth needed
Prerequisites: Target URL or list of URLs
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 2 stars
by bb33bb · poc
https://github.com/bb33bb/CVE-2022-22954-VMware-RCE

This repository contains a Python script designed to scan multiple URLs for the presence of CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access. The script uses a specific payload to trigger the vulnerability and checks the response to determine if the target is vulnerable.

Classification
Scanner 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware Workspace ONE Access
No auth needed
Prerequisites: List of target URLs in a text file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 1 stars
by corelight · poc
https://github.com/corelight/cve-2022-22954

This repository provides a detection package for CVE-2022-22954, a VMware vulnerability, by generating notices for exploit attempts and successes. It includes scripts for testing and coverage analysis but does not contain actual exploit code.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: VMware Workspace ONE Access
No auth needed
Prerequisites: VMware Workspace ONE Access instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by emilyastranova · poc
https://github.com/emilyastranova/VMware-CVE-2022-22954-Command-Injector

This is a functional proof-of-concept exploit for CVE-2022-22954, a command injection vulnerability in VMware Workspace ONE Access. It leverages a Freemarker template injection to execute arbitrary commands via a crafted GET request to the `/catalog-portal/ui/oauth/verify` endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware Workspace ONE Access (versions affected by CVE-2022-22954)
No auth needed
Prerequisites: Network access to the vulnerable VMware Workspace ONE Access instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 1 stars
by mumu2020629 · poc
https://github.com/mumu2020629/-CVE-2022-22954-scanner

This repository contains a scanner for CVE-2022-22954, a vulnerability in VMware Workspace ONE Access and related products. The scanner checks for the presence of the vulnerability by sending a crafted request to the target URL and analyzing the response.

Classification
Scanner 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware Workspace ONE Access, VMware Identity Manager, VMware Realize Automation
No auth needed
Prerequisites: Target URL list in a text file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 1 stars
by MSeymenD · poc
https://github.com/MSeymenD/CVE-2022-22954-Testi

This repository contains a Python script that checks for the presence of CVE-2022-22954, a server-side template injection vulnerability in VMware Workspace ONE Access and Identity Manager. The script sends a crafted request to the target URL and checks the response for indicators of vulnerability.

Classification
Scanner 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware Workspace ONE Access and Identity Manager
No auth needed
Prerequisites: Network access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by arzuozkan · poc
https://github.com/arzuozkan/CVE-2022-22954

This repository contains a README file describing research on CVE-2022-22954, a VMware Workspace ONE Access RCE vulnerability. No exploit code or technical details are provided.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Theoretical
Reliability
Theoretical
Target: VMware Workspace ONE Access
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by amit-pathak009 · poc
https://github.com/amit-pathak009/CVE-2022-22954

This repository contains a functional PoC for CVE-2022-22954, a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access and Identity Manager. The exploit allows remote command execution by injecting malicious payloads into the deviceUdid parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access and Identity Manager
No auth needed
Prerequisites: Network access to the vulnerable VMware Workspace ONE Access or Identity Manager instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by secfb · poc
https://github.com/secfb/CVE-2022-22954

This repository contains a Python-based PoC for CVE-2022-22954, a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access and Identity Manager. The exploit allows remote command execution by injecting malicious payloads into the deviceUdid parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access and Identity Manager
No auth needed
Prerequisites: Network access to the vulnerable VMware Workspace ONE Access or Identity Manager instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by amit-pathak009 · poc
https://github.com/amit-pathak009/CVE-2022-22954-PoC

This PoC exploits CVE-2022-22954, a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access and Identity Manager, allowing remote command execution. The script supports multiple modes (Shodan, file-based, manual) to identify and exploit vulnerable targets.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access and Identity Manager
No auth needed
Prerequisites: Target must be running a vulnerable version of VMware Workspace ONE Access/Identity Manager · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by nguyenv1nK · poc
https://github.com/nguyenv1nK/CVE-2022-22954

This repository provides a detailed analysis of CVE-2022-22954, a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access and related products. It includes setup instructions, path analysis, and exploitation steps using Freemarker template injection.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access (v21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0), VMware Identity Manager (v3.3.6, 3.3.5, 3.3.4, 3.3.3), VMware vRealize Automation (v8.x, 7.6), VMware Cloud Foundation (v4.x, 3.x), vRealize Suite Lifecycle Manager (8.x)
No auth needed
Prerequisites: Access to the target application · Ability to send crafted HTTP requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Jun-5heng · remote
https://github.com/Jun-5heng/CVE-2022-22954

This repository contains a Python-based exploit for CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access. The exploit leverages a Freemarker template injection to execute arbitrary commands on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access
No auth needed
Prerequisites: Network access to the target system · Target system running vulnerable VMware Workspace ONE Access
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by mhurts · poc
https://github.com/mhurts/CVE-2022-22954-POC

This PoC exploits CVE-2022-22954, a Freemarker template injection vulnerability in VMware Workspace ONE Access, by sending crafted HTTP requests to trigger remote code execution via the `freemarker.template.utility.Execute` class.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware Workspace ONE Access (versions 20.10.0.0, 20.10.0.1, 21.08.0.0, 21.08.0.1), VMware Identity Manager (versions 3.3.3-3.3.6), VMware Realize Automation (version 7.6)
No auth needed
Prerequisites: Network access to the target VMware Workspace ONE Access instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by lucksec · poc
https://github.com/lucksec/VMware-CVE-2022-22954

This repository contains a Python script and a README demonstrating a Server-Side Template Injection (SSTI) vulnerability in VMware Workspace ONE Access (CVE-2022-22954). The exploit leverages Freemarker template injection to execute arbitrary commands (e.g., `cat /etc/passwd`) via a crafted GET request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMware Workspace ONE Access
No auth needed
Prerequisites: Network access to the vulnerable VMware Workspace ONE Access instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
vulncheck_xdb WRITEUP
remote
https://github.com/pedrib/PoC

This repository contains a detailed technical writeup for CVE-2022-22954, which involves an unauthenticated remote code execution vulnerability in Cisco Nexus Dashboard Fabric Controller (formerly DCNM). The vulnerability is due to unsafe Flex AMF Java object deserialization and insecure sudo permissions, allowing an attacker to achieve root access.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cisco Nexus Dashboard Fabric Controller (formerly DCNM) versions 11.5(1) and 11.5(2)
No auth needed
Prerequisites: Network access to the target system · Flex AMF endpoint exposed
devstral-2 · analyzed Feb 25, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by mr_me, Udhaya Prakash, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/vmware_workspace_one_access_cve_2022_22954.rb

This Metasploit module exploits CVE-2022-22954, an unauthenticated server-side template injection (SSTI) in VMware Workspace ONE Access, to execute shell commands as the 'horizon' user. It leverages Freemarker template utility to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Workspace ONE Access
No auth needed
Prerequisites: Network access to the target system · VMware Workspace ONE Access instance vulnerable to CVE-2022-22954
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

VMware Workspace ONE Access - Server-Side Template Injection
CRITICALby sherlocksecurity
Shodan: http.favicon.hash:-1250474341
FOFA: icon_hash=-1250474341 || app="vmware-workspace-one-access" || app="vmware-identity-manager" || app="vmware-vrealize"

Scores

CVSS v3 9.8
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-04-14
VulnCheck KEV 2022-04-06
InTheWild.io 2022-04-13
ENISA EUVD EUVD-2022-28077
Ransomware Use Confirmed
CWE
CWE-94
Status published
Products (11)
vmware/cloud_foundation 4.0 - 4.3.1
vmware/identity_manager 3.3.3
vmware/identity_manager 3.3.4
vmware/identity_manager 3.3.5
vmware/identity_manager 3.3.6
vmware/vrealize_automation 7.6
vmware/vrealize_suite_lifecycle_manager 8.0 - 8.2
vmware/workspace_one_access 20.10.0.0
vmware/workspace_one_access 20.10.0.1
vmware/workspace_one_access 21.08.0.0
... and 1 more
Published Apr 11, 2022
KEV Added Apr 14, 2022
Tracked Since Feb 18, 2026