Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.3
CVE-2026-47866: VMware Avi Load Balancer Unauthorized Network Access
CVE-2026-47866
CVE-2026-47866
Summary
A malicious actor on the network can access some Avi Load Balancer features without permission. This could allow them to view or modify certain settings. VMware has released patches to fix this issue, so it's essential to update your Avi Load Balancer to the latest version.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vmware | avi load balancer | 32.1.1 |
Original title
VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization.
Affecte...
Original description
VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd CVSS3.1
8.3
Vulnerability type
CWE-863
Incorrect Authorization
Published: 18 Jul 2026 · Updated: 20 Jul 2026 · First seen: 18 Jul 2026