CVE-2026-47870: VMware Avi Load Balancer Privilege Escalation Vulnerability
VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code.
Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VMware Avi Load Balancer Privilege Escalation Vulnerabilityto a version that resolves this vulnerability.Fixed in 30.2.7 - Upgrade
Upgrade
VMware Avi Load Balancer Privilege Escalation Vulnerabilityto a version that resolves this vulnerability.Fixed in 31.2.2-2p3 - Upgrade
Upgrade
VMware Avi Load Balancer Privilege Escalation Vulnerabilityto a version that resolves this vulnerability.Fixed in 32.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47870?
The severity of CVE-2026-47870 is classified as high with a score of 7.1.
How do I fix CVE-2026-47870?
To fix CVE-2026-47870, upgrade to VMware Avi Load Balancer version 32.1.2, 31.2.2-2p3, or 30.2.7 depending on your current version.
What is CVE-2026-47870?
CVE-2026-47870 is a privilege escalation vulnerability in VMware Avi Load Balancer that allows a malicious authenticated user to execute remote code.
Which versions of VMware Avi Load Balancer are affected by CVE-2026-47870?
Affected versions include 32.1.1, 31.1.1 through 31.2.2, and 30.1.1 through 30.2.6.
Who might be impacted by CVE-2026-47870?
Any organization using VMware Avi Load Balancer with affected versions and that has authenticated users with network access may be at risk.