Junglewise Threat Intelligence

CVE-2026-47867: VMware Avi Load Balancer remote code execution in Control Plane

CVE-2026-47867 · Severity: high · CVSS 8.7 · Published 2026-07-18

Technologies: VMware Avi Load Balancer. Vendors: VMware.

Executive brief

VMware Avi Load Balancer is a software-defined platform used to manage application delivery and traffic across data centers and clouds. A security vulnerability in the management component (Control Plane) could allow a malicious user to take full control of the system and execute unauthorized commands. This could lead to a complete compromise of the load balancing infrastructure and the data passing through it.

Technical details

VMware Avi Load Balancer is vulnerable to remote code execution (RCE) due to improper control of generation of code (CWE-94) within the Avi Control Plane. An attacker with network access and high privileges (PR:H) can exploit this flaw to execute arbitrary commands on the underlying system. The vulnerability has a CVSS score of 8.7, notably featuring a Scope change (S:C), indicating that an exploit can impact components beyond the immediate security scope of the load balancer. Patches have been released in versions 32.1.2, 31.2.2-2p3, and 30.2.7.

Affected products

  • VMware Avi Load Balancer 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, 22.1.1 through 22.1.7

Timeline

  • 2026-07-14: advisory: Initial publication of VMSA-2026-0005 by Broadcom/VMware
  • 2026-07-18: disclosed: NVD publication date

References

Related threats