CVE-2026-47866: VMware Avi Load Balancer Authorization Bypass Vulnerability
VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization.
Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 30.2.7 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 31.2.2-2p3 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 32.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47866?
The severity of CVE-2026-47866 is high with a score of 8.3.
How do I fix CVE-2026-47866?
You can fix CVE-2026-47866 by upgrading to VMware Avi Load Balancer version 32.1.2 or 31.2.2-2p3.
What is the impact of CVE-2026-47866?
CVE-2026-47866 allows a malicious actor on the network to access parts of the Avi Control Plane without proper authorization.
Which versions of VMware Avi Load Balancer are affected by CVE-2026-47866?
Affected versions include 32.1.1, 31.1.1 through 31.2.2, and 30.1.1 through 30.2.6.
What type of vulnerability is CVE-2026-47866?
CVE-2026-47866 is classified as an authorization bypass vulnerability.