VMware Aria Automation 8.18.1 Flagged for Vulnerability CVE-2026-3479 Under PID 304845
search cancel

VMware Aria Automation 8.18.1 Flagged for Vulnerability CVE-2026-3479 Under PID 304845

book

Article ID: 440589

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

Nodes in VMware Aria Automation are flagged by security scans as vulnerable to PID 304845, which includes CVE-2026-3479 (CVSS 9.1). Engineering investigation confirms that the vulnerability affects the Orchestrator component within the VMware Aria Automation environment.

Environment

VMware Aria Automation 8.18.1

Cause

A security flaw exists within the specific build of the Orchestrator service packaged with the release of VMware Aria Automation 8.18.1.

Resolution

Upgrade to VMware Aria Automation Orchestrator 8.18.1 Update 5 (or later). The VMware Aria Automation 8.18.1 Cumulative Update #5 contains the engineered patch that resolves CVE-2026-3479.

 

For more information, refer to the VMware Aria Automation Release Notes.