Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Omnissa Workspace One UEM SSRF (CVE-2021-22054)

Historical catalog analysis: CISA added this entry on March 09, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.

What the vulnerability is

CVE-2021-22054 is a Server-Side Request Forgery (SSRF) vulnerability identified in Omnissa Workspace One UEM (formerly VMware Workspace One UEM). This flaw allows an unauthenticated actor who has network access to the UEM environment to send crafted requests that could result in the unauthorized retrieval of sensitive information.

Exposure and applicability

This vulnerability applies to organizations deploying Omnissa Workspace One UEM. The primary exposure path is network-level access to the UEM server; an attacker does not require valid credentials to exploit the SSRF flaw. Because this affects a unified endpoint management system, the sensitivity of the information potentially accessible via this vector is high, as these systems typically manage wide arrays of corporate devices and configurations.

Remediation priorities

Based on our analysis, vulnerability management teams should prioritize the following actions to reduce exposure:

  1. Vendor Mitigation Deployment: The primary corrective action is the application of mitigations specified in the vendor’s instructions. This should be the first priority for all affected installations.
  2. Cloud Service Review: For organizations utilizing cloud-based deployments, we recommend reviewing configurations against BOD 22-01 guidance to ensure that cloud service provider responsibilities and customer-managed controls are aligned.
  3. Service Decommissioning: In scenarios where vendor mitigations cannot be applied or are unavailable for a specific legacy version, the source indicates that discontinuing use of the product is a necessary alternative to eliminate the risk.

How to validate remediation

To assure that exposure has been reduced, defenders should move beyond simple version checks. We recommend the following validation approach:

  • Configuration Audit: Verify that the specific mitigations outlined by the vendor are active and correctly configured within the UEM environment.
  • Network Access Verification: Confirm that network-level access to the UEM server is restricted to authorized segments, reducing the surface area available for unauthenticated SSRF attempts.

Verification is complete only when the applied fix is confirmed through these configuration audits; a version number alone does not guarantee that the mitigation was successfully deployed or that compensating network controls are functioning as intended.

Limits and open questions

There are several unknowns regarding this vulnerability. The source lists the use of this flaw in known ransomware campaigns as “Unknown,” meaning defenders cannot assume it is currently being leveraged by specific threat actors, nor can they assume it is not. Additionally, while vendor instructions provide the path to remediation, the specific technical details of the SSRF trigger are not detailed in the summary, leaving a gap in the ability to create custom detection signatures without further vendor-provided telemetry.

Source and editorial note

CVE-2021-22054: Omnissa Workspace ONE Server-Side Request Forgery · Source date: March 09, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Archive date: March 12, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 18, 2026 at 01:02 UTC.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment