CVE-2026-47867
8.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Summary
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely.
Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| VMware | Avi Load Balancer | 32.1.1 | affected |
| VMware | Avi Load Balancer | 31.1.1 <= 31.2.2 | affected |
| VMware | Avi Load Balancer | 30.1.1 <= 30.2.6 | affected |
| VMware | Avi Load Balancer | 22.1.1 <= 22.1.7 | affected |
Weaknesses
- CWE-94: Improper Control of Generation of Code ('Code Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.