Description
VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
Published: 2026-07-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

VMware Avi Load Balancer is vulnerable to directory traversal due to insufficient validation of file paths. An attacker who has valid network credentials can supply crafted path components that cause the system to resolve to files outside the intended directory. This can lead to reading sensitive configuration files or other data that should be restricted, potentially exposing secrets, service accounts or system details. The vulnerability is a high‑severity flaw, reflected in a CVSS score of 8.8, but it does not provide arbitrary code execution or privilege escalation by itself. The primary confidentiality impact is data disclosure that might assist in further attacks.

Affected Systems

The affected product is VMware Avi Load Balancer. Versions vulnerable include 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7) and 22.1.1 through 22.1.7 (fixed in 30.2.7).

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating a high level of risk. The EPSS score is below 1 %, suggesting that, although the vulnerability is severe, the probability of exploitation is currently low. It is not listed in the CISA KEV catalog. The exploit requires an authenticated network user; an attacker with valid credentials could request a file using a path that includes traversal sequences. Holding appropriate privileges, the attacker might view files outside the trusted scope, which can lead to information leaks and additional compromise opportunities.

Generated by OpenCVE AI on July 30, 2026 at 23:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade VMware Avi Load Balancer to version 32.1.2 or later for 32.x releases, to 31.2.2‑2p3 for 31.x releases, and to 30.2.7 for 30.x and 22.x releases.
  • Restrict network user accounts to the minimum necessary permissions, ensuring they cannot access sensitive configuration files.
  • Enable and monitor logging for file access requests that include directory traversal patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on July 30, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware vmware Avi Load Balancer
Vendors & Products Vmware
Vmware vmware Avi Load Balancer

Mon, 20 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Title VMware Avi Load Balancer Directory Traversal Vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Vmware Vmware Avi Load Balancer
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-23T03:56:20.090Z

Reserved: 2026-05-20T10:00:57.077Z

Link: CVE-2026-47871

cve-icon Vulnrichment

Updated: 2026-07-20T15:25:36.333Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:30:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')