Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-47865: VMware Avi Load Balancer Authentication Bypass Risk
CVE-2026-47865
CVE-2026-47865
Summary
VMware Avi Load Balancer versions 31.1.1 to 31.2.2 and earlier versions 30.1.1 to 30.2.6 and 22.1.1 to 22.1.7 may allow unauthorized access to the system. This is a security risk because a malicious user could potentially access the system without needing a password. To fix this issue, update to version 31.2.2-2p3 for versions 31.1.1 to 31.2.2, or update to version 30.2.7 for versions 30.1.1 to 30.2.6 and 22.1.1 to 22.1.7.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vmware | avi load balancer | <= 31.2.2 |
Original title
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism....
Original description
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.
Affected versions:
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected versions:
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd CVSS3.1
9.8
Vulnerability type
CWE-287
Improper Authentication
Published: 18 Jul 2026 · Updated: 20 Jul 2026 · First seen: 18 Jul 2026