Junglewise Threat Intelligence

CVE-2026-47869: VMware Avi Load Balancer code injection in Avi Control Plane

CVE-2026-47869 · Severity: high · CVSS 8.7 · Published 2026-07-18

Technologies: VMware Avi Load Balancer. Vendors: VMware.

Executive brief

VMware Avi Load Balancer, a platform used to manage application delivery and traffic across data centers and clouds, is affected by a remote code execution vulnerability. An attacker who has already gained access to the system as an authenticated user can exploit this flaw to inject and run unauthorized commands. This could lead to a complete takeover of the load balancer, potentially allowing the attacker to intercept traffic or disrupt application availability.

Technical details

VMware Avi Load Balancer is vulnerable to remote code execution (RCE) due to improper control of generation of code (CWE-94). The vulnerability allows an authenticated attacker with network access to the Avi Control Plane to inject and execute arbitrary code. While the attack requires authentication, the CVSS vector indicates high privileges (PR:H) are required, but the impact is significant as it involves a scope change (S:C), potentially affecting the underlying host or integrated environments. Patches have been released in versions 32.1.2, 31.2.2-2p3, and 30.2.7.

Affected products

  • VMware Avi Load Balancer 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, 22.1.1 through 22.1.7

Timeline

  • 2026-07-14: advisory: Initial publication by Broadcom/VMware (VMSA-2026-0005)
  • 2026-07-18: disclosed: NVD publication date

References

Related threats