Description
VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
Published: 2026-07-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious authenticated user with network access can leverage a privilege escalation flaw in VMware Avi Load Balancer to execute arbitrary code remotely. The vulnerability arises from improper access control checks, allowing an attacker who has authenticated credentials to attain higher privileges and run unauthorized commands. The impact is elevated to any user or host that can interact with the affected instance, potentially compromising confidentiality, integrity, and availability of the load balancer and connected services.

Affected Systems

VMware Avi Load Balancer versions 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7 are affected. The fix versions are 32.1.2, 31.2.2-2p3, 30.2.7, and 30.2.7 for the older release stream.

Risk and Exploitability

The CVSS score of 7.1 reflects a high severity, but the EPSS score of less than 1% indicates a very low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely observed in the wild. Attackers would need authenticated network access to the load balancer, which is likely limited to internal administrators or application users, thereby reducing the attack surface compared to non-authenticated vectors.

Generated by OpenCVE AI on July 30, 2026 at 23:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for the affected Avi Load Balancer version
  • Remove or disable accounts that have access to the load balancer if they are not required for legitimate operations
  • Configure network segmentation to limit which hosts can reach the load balancer management interface

Generated by OpenCVE AI on July 30, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware vmware Avi Load Balancer
Vendors & Products Vmware
Vmware vmware Avi Load Balancer

Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Title VMware Avi Load Balancer Privilege Escalation Vulnerability
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Vmware Vmware Avi Load Balancer
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-24T20:17:47.315Z

Reserved: 2026-05-20T10:00:57.077Z

Link: CVE-2026-47870

cve-icon Vulnrichment

Updated: 2026-07-20T15:25:09.587Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:30:08Z

Weaknesses
  • CWE-269

    Improper Privilege Management