Vulnary
← back to the feed
Critical· 9.8official fix available

CVE-2026-47865

VMware Avi Load Balancer has a critical authentication bypass flaw that lets a remote attacker with network access reach the Avi Control plane without credentials. The issue affects several version lines, but VMware has released fixed builds.

publishedJul 18, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
55th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 18, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Organizations running VMware Avi Load Balancer versions 31.1.1–31.2.2, 30.1.1–30.2.6, or 22.1.1–22.1.7.

02

Real-world impact

An attacker who can reach the load balancer over the network could bypass authentication and gain control of the Avi Control plane, potentially compromising confidentiality, integrity, and availability of the load balancing infrastructure.

03

Why this severity

CVSS 9.8 (critical) means the flaw is easy to exploit over the network with no privileges or user interaction required, and can fully compromise the affected system.

04

What to do about it

official fix available
recommended steps
  1. 01If you are running VMware Avi Load Balancer 31.1.1 through 31.2.2, upgrade to version 31.2.2-2p3 or later.
  2. 02If you are running VMware Avi Load Balancer 30.1.1 through 30.2.6, upgrade to version 30.2.7 or later.
  3. 03If you are running VMware Avi Load Balancer 22.1.1 through 22.1.7, upgrade to version 30.2.7 or later.
  4. 04After upgrading, verify the installed version and confirm the Avi Control plane is accessible only with proper authentication.

NVD-referenced vendor advisory (version fix information from NVD description)

05

Timeline

  1. Jul 18, 2026 · 15d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 19, 2026 · 15d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
  3. Jul 23, 2026 · 10d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →