Executive brief
VMware Avi Load Balancer, a platform used to manage application delivery and traffic across data centers and clouds, contains a critical security flaw. An attacker with network access can bypass authentication to gain unauthorized access to the management control plane. This could allow a malicious actor to take full control of the load balancing infrastructure, potentially leading to data theft or service disruption.
Technical details
VMware Avi Load Balancer is vulnerable to an authentication bypass (CWE-287) within its Control Plane component. The vulnerability allows a remote, unauthenticated attacker with network access to the controller to bypass the authentication mechanism entirely. Successful exploitation grants the attacker access to the Avi Control plane, potentially leading to full administrative control over the load balancing environment. The issue affects multiple release branches including 22.x, 30.x, and 31.x, and has been addressed in versions 31.2.2-2p3 and 30.2.7.
Affected products
- VMware Avi Load Balancer 31.1.1 through 31.2.2; 30.1.1 through 30.2.6; 22.1.1 through 22.1.7
Timeline
- 2026-07-14: advisory: Initial advisory VMSA-2026-0005 published by Broadcom
- 2026-07-18: disclosed: NVD publication date