Executive brief
VMware Avi Load Balancer, a platform used to manage application delivery and traffic, contains a security flaw that allows a user with existing access to the system to increase their permissions. If exploited, an attacker could gain full administrative (root) control over the load balancer. This could lead to unauthorized access to sensitive traffic data or the disruption of network services.
Technical details
VMware Avi Load Balancer is vulnerable to local privilege escalation (CWE-269) due to improper privilege management. An attacker who has already gained local access to the system with low-level privileges can exploit this flaw to execute arbitrary code with root-level permissions. The vulnerability affects multiple versions including the 22.x, 30.x, 31.x, and 32.x branches. Broadcom has released patches (versions 32.1.2, 31.2.2-2p3, and 30.2.7) to address this issue. No workarounds are currently available.
Affected products
- VMware Avi Load Balancer 32.1.1, 31.1.1 - 31.2.2, 30.1.1 - 30.2.6, 22.1.1 - 22.1.7
Timeline
- 2026-07-14: advisory: Initial publication by Broadcom (VMSA-2026-0005)
- 2026-07-18: disclosed: NVD publication date