Description
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
Published: 2026-07-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in VMware Avi Load Balancer is a code injection flaw (CWE‑94) that allows a malicious, authenticated user with network access to supply input to the vulnerable component and execute arbitrary code on the appliance. Successful exploitation grants the attacker full control over the load balancer and any functions it provides, and the attacker operates with the privileges of the authenticated session used to deliver the payload.

Affected Systems

The vulnerability affects the VMware Avi Load Balancer product. Affected releases are 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (fixed in 30.2.7).

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% shows a very low yet nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a malicious user who is already authenticated and has network access to the load balancer’s management interface; exploitation requires such access and is unlikely to occur via the public Internet. Given the high impact, organizations should treat the vulnerability as a critical risk and remediate promptly.

Generated by OpenCVE AI on July 30, 2026 at 23:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update VMware Avi Load Balancer to the latest fixed release—32.1.2 for the 32.x series, 31.2.2‑2p3 for the 31.x series, or 30.2.7 for the 30.x and 22.x series.
  • Restrict network access to the appliance’s management interfaces so that only trusted, authenticated users can reach them, and apply firewall rules to block unsolicited inbound traffic.
  • If an immediate patch cannot be applied, mitigate by disabling remote configuration features or placing the load balancer behind a dedicated VLAN to limit attacker movement.

Generated by OpenCVE AI on July 30, 2026 at 23:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware vmware Avi Load Balancer
Vendors & Products Vmware
Vmware vmware Avi Load Balancer

Thu, 23 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Title VMware Avi Load Balancer Remote Code Execution Vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Vmware Vmware Avi Load Balancer
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-23T03:56:18.600Z

Reserved: 2026-05-20T10:00:57.077Z

Link: CVE-2026-47869

cve-icon Vulnrichment

Updated: 2026-07-20T15:24:39.015Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:30:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')