PT-2026-58856 · Vmware · Avi Load Balancer+1
CVE-2026-47865
·
Published
2026-07-14
·
Updated
2026-07-23
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VMware Avi Load Balancer versions 31.1.1 through 31.2.2
VMware Avi Load Balancer versions 30.1.1 through 30.2.6
VMware Avi Load Balancer versions 22.1.1 through 22.1.7
Description
An authentication bypass exists in the Avi Controller (control plane) due to an authentication and authorization logic flaw. This improper authentication fails to correctly enforce identity checks before granting access to the control plane. A malicious user with network access can remotely exploit this by sending crafted requests to bypass the authentication mechanism without valid credentials. Successful exploitation allows unauthorized access to management interfaces, potentially leading to full compromise of the load balancer management plane, configuration takeover, and service disruption.
Recommendations
Update versions 31.1.1 through 31.2.2 to 31.2.2-2p3.
Update versions 30.1.1 through 30.2.6 to 30.2.7.
Update versions 22.1.1 through 22.1.7 to 30.2.7.
Fix
RCE
LPE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avi Controller
Avi Load Balancer