Executive brief
VMware Avi Load Balancer is a software-defined application delivery controller used to manage network traffic and ensure application availability. A security flaw allows an attacker with network access to bypass authorization checks and access sensitive parts of the management interface. This could lead to unauthorized configuration changes or exposure of internal operational data.
Technical details
The vulnerability is classified as an incorrect authorization (CWE-863) within the Avi Control Plane component of VMware Avi Load Balancer. An attacker with network access and low-level privileges (PR:L) can bypass intended access controls to interact with a subset of the management interface. This could allow for unauthorized data retrieval or modification of specific control plane functions. The issue affects multiple major version branches and has been addressed in versions 32.1.2, 31.2.2-2p3, and 30.2.7.
Affected products
- VMware Avi Load Balancer 32.1.1, 31.1.1 - 31.2.2, 30.1.1 - 30.2.6, 22.1.1 - 22.1.7
Timeline
- 2026-07-14: advisory: Initial publication by Broadcom/VMware (VMSA-2026-0005)
- 2026-07-18: disclosed: NVD publication date