PT-2026-58856 · Vmware · Avi Load Balancer+1

CVE-2026-47865

·

Published

2026-07-14

·

Updated

2026-07-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware Avi Load Balancer versions 31.1.1 through 31.2.2 VMware Avi Load Balancer versions 30.1.1 through 30.2.6 VMware Avi Load Balancer versions 22.1.1 through 22.1.7
Description An authentication bypass exists in the Avi Controller (control plane) due to an authentication and authorization logic flaw. This improper authentication fails to correctly enforce identity checks before granting access to the control plane. A malicious user with network access can remotely exploit this by sending crafted requests to bypass the authentication mechanism without valid credentials. Successful exploitation allows unauthorized access to management interfaces, potentially leading to full compromise of the load balancer management plane, configuration takeover, and service disruption.
Recommendations Update versions 31.1.1 through 31.2.2 to 31.2.2-2p3. Update versions 30.1.1 through 30.2.6 to 30.2.7. Update versions 22.1.1 through 22.1.7 to 30.2.7.

Fix

RCE

LPE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47865

Affected Products

Avi Controller
Avi Load Balancer