Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-47871: VMware Avi Load Balancer allows unauthorized access

CVE-2026-47871 CVE-2026-47871
Summary

The VMware Avi Load Balancer has a security flaw that allows a malicious user with a valid account to access parts of the system they shouldn't be able to. This could lead to unauthorized changes or data exposure. To fix this, update to the latest version of the software.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
vmware avi load balancer 32.1.1
Original title
VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected v...
Original description
VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd CVSS3.1 8.8
Vulnerability type
CWE-22 Path Traversal
Published: 18 Jul 2026 · Updated: 20 Jul 2026 · First seen: 18 Jul 2026