CVE-2026-47867: VMware Avi Load Balancer Remote Code Execution Vulnerability
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely.
Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 30.2.7 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 31.2.2-2p3 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 32.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47867?
CVE-2026-47867 has a high severity score of 8.7.
How do I fix CVE-2026-47867?
To fix CVE-2026-47867, upgrade to VMware Avi Load Balancer version 32.1.2 or the fixed versions 31.2.2-2p3 and 30.2.6.
What impact does CVE-2026-47867 have on my system?
CVE-2026-47867 allows remote code execution by a malicious user with network access to the Avi Control plane.
What versions of VMware Avi Load Balancer are affected by CVE-2026-47867?
Affected versions include 32.1.1, 31.1.1 through 31.2.2, and 30.1.1 through 30.2.6.
Is there a known exploit for CVE-2026-47867?
Yes, CVE-2026-47867 is a remote code execution vulnerability that can be exploited by unauthorized users.