Description
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
Published: 2026-07-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in VMware Avi Load Balancer permits an attacker with network access to send specially crafted input to the Avi Control plane, leading to arbitrary code execution (CWE‑94). Successful exploitation provides the attacker full control over the load balancer system, compromising the confidentiality, integrity, and availability of all services managed by it.

Affected Systems

Affected products include VMware Avi Load Balancer. Versions 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (fixed in 30.2.7) are vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, meaning no known active exploitation has been reported, yet the potential impact warrants prompt action. Exploitation requires network‑level access to the Avi Control plane; isolating this plane from untrusted networks and applying the vendor patch are the most effective defenses.

Generated by OpenCVE AI on July 30, 2026 at 23:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch: upgrade VMware Avi Load Balancer to 32.1.2, 31.2.2‑2p3, 30.2.7, or newer, depending on your current version.
  • Restrict network access to the Avi Control plane by enforcing firewall rules or network segmentation, allowing only trusted administrators to connect.
  • Implement active monitoring for anomalous command execution or unexpected traffic patterns on the Avi Control plane to detect potential exploitation attempts.

Generated by OpenCVE AI on July 30, 2026 at 23:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware vmware Avi Load Balancer
Vendors & Products Vmware
Vmware vmware Avi Load Balancer

Mon, 20 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Title VMware Avi Load Balancer Remote Code Execution Vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Vmware Vmware Avi Load Balancer
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-23T03:56:17.181Z

Reserved: 2026-05-20T10:00:57.077Z

Link: CVE-2026-47867

cve-icon Vulnrichment

Updated: 2026-07-20T15:23:22.788Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:30:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')