← All Advisories

Unauthenticated Network Attacker Can Access the VMware Avi Load Balancer Control Plane and Execute Code Remotely

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-47867

Key Details

CVECVE-2026-47867
CVSS Score / Version8.7 (High) / CVSS v3.1
Updated2026-08-20
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsBroadcom vmware_avi_load_balancer
Classified asCWE-94 (Improper Control of Generation of Code ('Code Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Broadcomvmware_avi_load_balancer
SubsystemsGeneral OT
SectorsMultiple

What to Know

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely.

Affected versions:

32.1.1 (fixed in 32.1.2)

31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)

30.1.1 through 30.2.6 (fixed in 30.2.7)

22.1.1 through 22.1.7 (fixed in 30.2.7) (NVD)

What to Do

Monitor Broadcom's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-47867
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-47867
Vendor advisoryhttps://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926