CVE-2026-47866
8.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Summary
VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization.
Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| VMware | Avi Load Balancer | 32.1.1 | affected |
| VMware | Avi Load Balancer | 31.1.1 <= 31.2.2 | affected |
| VMware | Avi Load Balancer | 30.1.1 <= 30.2.6 | affected |
| VMware | Avi Load Balancer | 22.1.1 <= 22.1.7 | affected |
Weaknesses
- CWE-863: Incorrect Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.