CVE-2022-2225
CVE-2022-2225 is a high-severity vulnerability in Cloudflare Warp with a CVSS 3.x base score of 8.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-284.
Key facts
- Severity: High (CVSS 3.x base score 8.1)
- EPSS exploit prediction: 0% (9th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-284
- Affected product: Cloudflare Warp
- Published:
- Last modified:
Description
By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies) and features such as 'Lock WARP switch'.
Frequently asked questions
- What is CVE-2022-2225?
- By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies) and features such as 'Lock WARP switch'.
- How severe is CVE-2022-2225?
- CVE-2022-2225 has a CVSS 3.x base score of 8.1, rated high severity. It is exploitable over local access with low attack complexity, requires low privileges and user interaction. Impact on confidentiality is low, integrity high, and availability high.
- Is CVE-2022-2225 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (9th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2022-2225?
- CVE-2022-2225 primarily affects Cloudflare Warp. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2022-2225?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2022-2225 published?
- CVE-2022-2225 was published on 2022-07-26 and last updated on 2026-06-17.
References
Affected products (3)
- cpe:2.3:a:cloudflare:warp:*:*:*:*:*:macos:*:*
- cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:*
- cpe:2.3:a:cloudflare:warp:*:*:*:*:*:linux:*:*
More vulnerabilities in Cloudflare Warp
- CVE-2022-4428 — High (CVSS 8.9): support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for…
- CVE-2023-2754 — High (CVSS 7.4): The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local…
- CVE-2023-1862 — High (CVSS 7.3): Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the…
- CVE-2025-0651 — High (CVSS 7.1): Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low…
- CVE-2023-0652 — High (CVSS 7.0): Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of…
- CVE-2023-1412 — High (CVSS 7.0): An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for…
All CVEs affecting Cloudflare Warp →
Other CWE-284 (Improper Access Control) vulnerabilities
- CVE-2026-76607 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.
- CVE-2026-20315 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering…
- CVE-2026-70921 — Critical (CVSS 10.0): Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The…
- CVE-2026-66803 — Critical (CVSS 10.0): Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
- CVE-2026-58630 — Critical (CVSS 10.0): Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-60358 — Critical (CVSS 10.0): Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).…
Browse all CWE-284 (Improper Access Control) vulnerabilities →