Junglewise Threat Intelligence

CVE-2026-47866: VMware Avi Load Balancer authorization bypass in Avi Control Plane

CVE-2026-47866 · Severity: high · CVSS 8.3 · Published 2026-07-18

Technologies: VMware Avi Load Balancer. Vendors: VMware.

Executive brief

VMware Avi Load Balancer is a software-defined application delivery controller used to manage network traffic and ensure application availability. A security flaw allows an attacker with network access to bypass authorization checks and access sensitive parts of the management interface. This could lead to unauthorized configuration changes or exposure of internal operational data.

Technical details

The vulnerability is classified as an incorrect authorization (CWE-863) within the Avi Control Plane component of VMware Avi Load Balancer. An attacker with network access and low-level privileges (PR:L) can bypass intended access controls to interact with a subset of the management interface. This could allow for unauthorized data retrieval or modification of specific control plane functions. The issue affects multiple major version branches and has been addressed in versions 32.1.2, 31.2.2-2p3, and 30.2.7.

Affected products

  • VMware Avi Load Balancer 32.1.1, 31.1.1 - 31.2.2, 30.1.1 - 30.2.6, 22.1.1 - 22.1.7

Timeline

  • 2026-07-14: advisory: Initial publication by Broadcom/VMware (VMSA-2026-0005)
  • 2026-07-18: disclosed: NVD publication date

References

Related threats