Junglewise Threat Intelligence

CVE-2026-44925: Veritas InfoScale Operations Manager CSRF in VIOM web application

CVE-2026-44925 · Severity: info · Published 2026-05-20

Technologies: Veritas InfoScale Operations Manager. Vendors: Veritas.

Executive brief

Veritas InfoScale Operations Manager (VIOM), a tool used for managing complex storage and server environments, is vulnerable to an attack that can trick administrators into performing unintended actions. By convincing a logged-in user to click a malicious link, an attacker can modify settings or configurations within the management console without the user's consent. This could lead to unauthorized changes in the infrastructure management platform.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web interface of Veritas InfoScale Operations Manager (VIOM) version 9.1.3. The application fails to properly validate that requests are intentionally initiated by the authenticated user, likely due to missing or insufficient anti-CSRF tokens. An attacker can exploit this by hosting a malicious HTML page or link that, when visited by a user with an active VIOM session, submits unauthorized requests to the VIOM server. This can result in unauthorized configuration changes or state modifications within the management console. The attack requires network reachability to the victim and successful social engineering to induce the user to click the link.

Affected products

  • Veritas InfoScale Operations Manager (VIOM) 9.1.3

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: advisory

References

Related threats