Description
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.

Affected versions:
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
Published: 2026-07-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Avi Load Balancer suffers an authentication bypass that lets an attacker with network access reach the control plane without valid credentials. The vulnerability is a classic credential validation flaw (CWE‑287). An adversary who succeeds can read and modify configuration, disrupt traffic, or insert malicious policies, effectively gaining full control over load‑balancing services and potentially exposing protected data or routing traffic to malicious destinations.

Affected Systems

The vulnerability affects VMware’s Avi Load Balancer product across multiple major releases: versions 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (also fixed in 30.2.7). Any deployment running an affected version without the corresponding patch is vulnerable.

Risk and Exploitability

The CVSS score of 9.8 categorises this as critically severe. While the EPSS score of less than 1% suggests a modest exploitation probability, the lack of an existing CISA KEV listing does not diminish potential impact. The likely attack vector is through network access to the Avi control plane interface, requiring no special user privileges beyond network connectivity. Once accessed, an attacker can perform privileged configuration and potentially compromise the availability or integrity of the serving infrastructure.

Generated by OpenCVE AI on July 30, 2026 at 23:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch that upgrades to 31.2.2‑2p3, 30.2.7, or a later released version that contains the fix.
  • If a patch cannot be applied immediately, isolate the Avi Load Balancer control plane by restricting inbound network access to a secured subnet or enforce IP‑based firewall rules that allow traffic only from trusted management hosts.
  • Ensure that default or weak credentials are removed, enforce strong authentication, and monitor control‑plane API calls for anomalous activity.

Generated by OpenCVE AI on July 30, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware vmware Avi Load Balancer
Vendors & Products Vmware
Vmware vmware Avi Load Balancer

Mon, 20 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Title VMware Avi Load Balancer Authentication Bypass Vulnerability
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Vmware Vmware Avi Load Balancer
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-23T03:56:15.727Z

Reserved: 2026-05-20T10:00:57.076Z

Link: CVE-2026-47865

cve-icon Vulnrichment

Updated: 2026-07-20T15:22:07.900Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:30:08Z

Weaknesses