CVE-2026-47865: VMware Avi Load Balancer Authentication Bypass Vulnerability
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.
Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 30.2.7 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 31.2.2-2p3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47865?
The severity of CVE-2026-47865 is critical with a score of 9.8.
How do I fix CVE-2026-47865?
To fix CVE-2026-47865, upgrade to VMware Avi Load Balancer version 31.2.2-2p3 or 30.2.7.
What versions are affected by CVE-2026-47865?
Affected versions by CVE-2026-47865 include VMware Avi Load Balancer versions 31.1.1 through 31.2.2 and 30.1.1 through 30.2.6.
What type of vulnerability is CVE-2026-47865?
CVE-2026-47865 is an authentication bypass vulnerability in VMware Avi Load Balancer.
What are the potential impacts of CVE-2026-47865?
The potential impacts of CVE-2026-47865 include unauthorized access to the Avi Control plane by a malicious user.