CVE-2026-47865
VMware Avi Load Balancer has a critical authentication bypass flaw that lets a remote attacker with network access reach the Avi Control plane without credentials. The issue affects several version lines, but VMware has released fixed builds.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Organizations running VMware Avi Load Balancer versions 31.1.1–31.2.2, 30.1.1–30.2.6, or 22.1.1–22.1.7.
Real-world impact
An attacker who can reach the load balancer over the network could bypass authentication and gain control of the Avi Control plane, potentially compromising confidentiality, integrity, and availability of the load balancing infrastructure.
Why this severity
CVSS 9.8 (critical) means the flaw is easy to exploit over the network with no privileges or user interaction required, and can fully compromise the affected system.
What to do about it
- 01If you are running VMware Avi Load Balancer 31.1.1 through 31.2.2, upgrade to version 31.2.2-2p3 or later.
- 02If you are running VMware Avi Load Balancer 30.1.1 through 30.2.6, upgrade to version 30.2.7 or later.
- 03If you are running VMware Avi Load Balancer 22.1.1 through 22.1.7, upgrade to version 30.2.7 or later.
- 04After upgrading, verify the installed version and confirm the Avi Control plane is accessible only with proper authentication.
NVD-referenced vendor advisory (version fix information from NVD description)
Timeline
- Jul 18, 2026 · 15d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.