CVE-2026-47871: VMware Avi Load Balancer Directory Traversal Vulnerability
VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks.
Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 30.2.7 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 31.2.2-2p3 - Upgrade
Upgrade
VMware Avi Load Balancerto a version that resolves this vulnerability.Fixed in 32.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47871?
CVE-2026-47871 has a high severity rating of 8.8.
How do I fix CVE-2026-47871?
To fix CVE-2026-47871, upgrade to VMware Avi Load Balancer versions 32.1.2, 31.2.2-2p3, or later.
What type of vulnerability is CVE-2026-47871?
CVE-2026-47871 is a directory traversal vulnerability.
Who is affected by CVE-2026-47871?
Authenticated network users of affected VMware Avi Load Balancer versions are at risk due to CVE-2026-47871.
What are the affected versions for CVE-2026-47871?
The affected versions include VMware Avi Load Balancer 32.1.1, 31.1.1 through 31.2.2, and 30.1.1 through 30.2.6.