CVE-2026-47866 – VMware Avi Load Balancer
“When authentication and execution controls fail together, attackers can move from access to full system compromise.”
VMware has released security updates for Avi Load Balancer to address one Critical and six High severity vulnerabilities affecting multiple supported release branches. The update resolves weaknesses involving authentication bypass, authorization bypass, remote code execution, directory traversal, and privilege escalation. If exploited, these flaws could allow attackers to access the Avi Control Plane, execute arbitrary code, elevate privileges, or access restricted resources.
CVE-2026-47865 has a CVSS score of 9.8, Critical severity. CVE-2026-47866 has a CVSS score of 8.3, High severity. CVE-2026-47867 has a CVSS score of 8.7, High severity. CVE-2026-47869 has a CVSS score of 8.7, High severity. CVE-2026-47871 has a CVSS score of 8.8, High severity. CVE-2026-47868 has a CVSS score of 7.8, High severity. CVE-2026-47870 has a CVSS score of 7.1, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.
Affected versions include 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, 22.1.1 through 22.1.7, and selected 32.1.1 deployments, with fixes available in 32.1.2, 31.2.2-2p3, and 30.2.7, depending on the release branch.
Key Details
- Affected Product
- Broadcom Vmware Avi Load Balancer
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-863