Description
VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
Published: 2026-07-18
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

VMware Avi Load Balancer contains an authorization bypass vulnerability (CWE-863) that allows a malicious actor on the network to access a limited subset of the Avi Control Plane without proper authorization.

Affected Systems

The vulnerability affects VMware Avi Load Balancer. Affected versions are 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (fixed in 30.2.7).

Risk and Exploitability

The CVSS base score of 8.3 indicates a high potential impact if the vulnerability is exploited. The EPSS score is less than 1%, suggesting a low probability of active exploitation in the wild at present. The vulnerability is not listed in the CISA KEV catalog, so no documented exploit campaigns are known. The likely attack vector involves network traffic directed at Avi Control Plane endpoints, enabling unauthorized access to a constrained set of configuration interfaces without proper checks.

Generated by OpenCVE AI on July 30, 2026 at 23:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade VMware Avi Load Balancer to a version that includes the fix (32.1.2 or later, 31.2.2‑2p3 or later, or 30.2.7 or later).
  • Restrict network access to the Avi Control Plane by allowing traffic only from trusted hosts or subnet ranges.
  • Enforce firewall or ACL rules that block all other traffic to the control‑plane ports.

Generated by OpenCVE AI on July 30, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware vmware Avi Load Balancer
Vendors & Products Vmware
Vmware vmware Avi Load Balancer

Mon, 20 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Title VMware Avi Load Balancer Authorization Bypass Vulnerability
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Vmware Vmware Avi Load Balancer
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-23T03:56:16.450Z

Reserved: 2026-05-20T10:00:57.077Z

Link: CVE-2026-47866

cve-icon Vulnrichment

Updated: 2026-07-20T15:22:51.967Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:30:08Z

Weaknesses