CVE-2026-47868: VMware Avi Load Balancer Local Privilege Escalation Vulnerability
VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root.
Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 30.2.7 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 31.2.2-2p3 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 32.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47868?
The severity of CVE-2026-47868 is rated as high with a score of 7.8.
How do I fix CVE-2026-47868?
To fix CVE-2026-47868, upgrade to VMware Avi Load Balancer version 32.1.2 or 31.2.2-2p3.
What could an attacker do with CVE-2026-47868?
An attacker with local access could exploit CVE-2026-47868 to escalate their privileges and execute code as root.
Which versions of VMware Avi Load Balancer are affected by CVE-2026-47868?
Affected versions include VMware Avi Load Balancer 32.1.1, 31.1.1 through 31.2.2, and 30.1.1 through 30.2.6.
Is local access required to exploit CVE-2026-47868?
Yes, local access is required to exploit CVE-2026-47868.