CVE-2026-47869: VMware Avi Load Balancer Remote Code Execution Vulnerability
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code.
Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 30.2.7 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 31.2.2-2p3 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 32.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47869?
The severity of CVE-2026-47869 is rated high with a score of 8.7.
How do I fix CVE-2026-47869?
To fix CVE-2026-47869, upgrade to VMware Avi Load Balancer versions 32.1.2, 31.2.2-2p3, or 30.2.7.
What type of vulnerability is CVE-2026-47869?
CVE-2026-47869 is a remote code execution vulnerability.
Who is affected by CVE-2026-47869?
CVE-2026-47869 affects VMware Avi Load Balancer versions 22.1.1 and later as specified in the advisory.
Can an unauthenticated user exploit CVE-2026-47869?
No, CVE-2026-47869 requires the attacker to be an authenticated user with network access to exploit the vulnerability.