Junglewise Threat Intelligence

CVE-2026-47870: VMware Avi Load Balancer privilege escalation in Avi Control Plane

CVE-2026-47870 · Severity: high · CVSS 7.1 · Published 2026-07-18

Technologies: VMware Avi Load Balancer. Vendors: VMware.

Executive brief

VMware Avi Load Balancer, a platform used to manage application delivery and traffic across networks, contains a security flaw that allows an authenticated user to increase their access levels. By exploiting this vulnerability, a malicious user who already has basic access to the network could potentially execute unauthorized commands or code. This could lead to a significant breach of the system's integrity and the exposure of sensitive operational data.

Technical details

VMware Avi Load Balancer is vulnerable to privilege escalation (CWE-269) due to improper privilege management. An attacker must first be authenticated with low-level privileges (PR:L) and have network access to the Avi Control Plane. Successful exploitation allows the attacker to escalate their privileges, potentially leading to remote code execution. The vulnerability affects multiple major release branches including 22.x, 30.x, 31.x, and 32.x. Patches have been released in versions 32.1.2, 31.2.2-2p3, and 30.2.7.

Affected products

  • VMware Avi Load Balancer 32.1.1, 31.1.1 - 31.2.2, 30.1.1 - 30.2.6, 22.1.1 - 22.1.7

Timeline

  • 2026-07-14: advisory: Initial publication by Broadcom (VMSA-2026-0005)
  • 2026-07-18: disclosed: NVD publication date

References

Related threats