Unrated severityNVD Advisory· Published Jul 18, 2026· Updated Jul 23, 2026
VMware Avi Load Balancer Authorization Bypass Vulnerability
CVE-2026-47866
Description
VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization.
Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected products
2- Range: 32.1.1, 31.1.1-31.2.2, 30.1.1-30.2.6, 22.1.1-22.1.7
- Range: 32.1.1, 31.1.1-31.2.2, 30.1.1-30.2.6, 22.1.1-22.1.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.