Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-47869: VMware Avi Load Balancer allows unauthorized code execution
CVE-2026-47869
CVE-2026-47869
Summary
An attacker with access to the Avi Load Balancer can inject and run malicious code, potentially taking control of the system. This affects multiple versions of the software and can be mitigated by upgrading to the latest fixed version. VMware has released patches for the affected versions.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vmware | avi load balancer | 32.1.1 |
Original title
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code.
Affected versions:
32.1.1 (fixed...
Original description
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd CVSS3.1
8.7
Vulnerability type
CWE-94
Code Injection
Published: 18 Jul 2026 · Updated: 20 Jul 2026 · First seen: 18 Jul 2026