Executive brief
VMware Avi Load Balancer is a software-defined solution used to manage and distribute network traffic across servers. A security flaw in this product allows an authenticated user to bypass file access restrictions and view or modify sensitive system files. This could lead to the theft of confidential data or a complete takeover of the load balancing infrastructure.
Technical details
A directory traversal vulnerability (CWE-22) exists in VMware Avi Load Balancer due to insufficient validation of user-supplied file paths. An authenticated attacker with network access can exploit this flaw by submitting specially crafted requests containing sequences like '../' to escape the intended directory. Successful exploitation allows the attacker to read, and potentially modify or delete, sensitive files on the underlying operating system. The vulnerability is addressed in versions 32.1.2, 31.2.2-2p3, and 30.2.7.
Affected products
- VMware Avi Load Balancer 32.1.1, 31.1.1 - 31.2.2, 30.1.1 - 30.2.6, 22.1.1 - 22.1.7
Timeline
- 2026-07-14: advisory: Initial advisory published by Broadcom/VMware (VMSA-2026-0005)
- 2026-07-18: disclosed: CVE published to NVD