← All Advisories

VMware Avi Load Balancer 31.x Through 31.2.2 and 30.x Through 30.2.6 Authentication Bypass Lets Network-Accessible Attackers Reach the Avi Control Plane Without Valid Credentials

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-47865

Key Details

CVECVE-2026-47865
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-08-20
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsBroadcom vmware_avi_load_balancer
Classified asCWE-287 (Improper Authentication)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Broadcomvmware_avi_load_balancer
SubsystemsGeneral OT
SectorsMultiple

What to Know

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.

Affected versions:

31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)

30.1.1 through 30.2.6 (fixed in 30.2.7)

22.1.1 through 22.1.7 (fixed in 30.2.7) (NVD)

What to Do

Monitor Broadcom's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-47865
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-47865
Vendor advisoryhttps://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926