Executive brief
VMware Avi Load Balancer, a platform used to manage application delivery and traffic across networks, contains a security flaw that allows an authenticated user to increase their access levels. By exploiting this vulnerability, a malicious user who already has basic access to the network could potentially execute unauthorized commands or code. This could lead to a significant breach of the system's integrity and the exposure of sensitive operational data.
Technical details
VMware Avi Load Balancer is vulnerable to privilege escalation (CWE-269) due to improper privilege management. An attacker must first be authenticated with low-level privileges (PR:L) and have network access to the Avi Control Plane. Successful exploitation allows the attacker to escalate their privileges, potentially leading to remote code execution. The vulnerability affects multiple major release branches including 22.x, 30.x, 31.x, and 32.x. Patches have been released in versions 32.1.2, 31.2.2-2p3, and 30.2.7.
Affected products
- VMware Avi Load Balancer 32.1.1, 31.1.1 - 31.2.2, 30.1.1 - 30.2.6, 22.1.1 - 22.1.7
Timeline
- 2026-07-14: advisory: Initial publication by Broadcom (VMSA-2026-0005)
- 2026-07-18: disclosed: NVD publication date