Skip to content
VMwareCVE-2026-47866

VMware Avi Load Balancer: improper authorization

High8.3CVE-2026-47866 · Published Jul 18, 2026 · updated Aug 20, 2026

VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

VMware advisory

Affected versions

PackageAffectedFixed in
Avi Load Balancer
Product
<= 32.1.1No fix yet
>= 31.1.1, <= 31.2.2No fix yet
>= 30.1.1, <= 30.2.6No fix yet
>= 22.1.1, <= 22.1.7No fix yet
Details and references

More VMware advisories

All VMware
Advisory
VMware Avi Load Balancer: authentication bypass
Critical9.8Jul 18
VMware Avi Load Balancer: remote code execution
High8.7Jul 18
VMware Avi Load Balancer: privilege escalation
High7.8Jul 18
VMware Avi Load Balancer: remote code execution
High8.7Jul 18
VMware Avi Load Balancer: privilege escalation
High7.1Jul 18
VMware Avi Load Balancer: path traversal
High8.8Jul 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.