Junglewise Threat Intelligence

CVE-2026-22927: Omnissa Workspace ONE Tunnel local privilege escalation via path traversal

CVE-2026-22927 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Omnissa Workspace ONE Tunnel for Windows, a tool used to provide secure remote access to corporate applications, contains a security flaw that could allow a local user to gain elevated permissions. An attacker who already has basic access to a Windows computer could exploit this vulnerability to take full control of the system. This could lead to the theft of sensitive data or the disruption of corporate security controls.

Technical details

A local privilege escalation vulnerability exists in Omnissa Workspace ONE Tunnel for Windows prior to version 26.03. The flaw is rooted in a path traversal vulnerability (CWE-22) where the application fails to properly limit pathnames to restricted directories. A local attacker with low-privileged access can exploit this weakness to execute code or manipulate files with higher privileges, potentially gaining full SYSTEM-level access. The vulnerability is tracked as CVE-2026-22927 and has been addressed in version 26.03.

Affected products

  • Omnissa Workspace ONE Tunnel for Windows prior to 26.03

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory

References