CVE-2026-47868
published 2026-07-18CVE-2026-47868: VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.11%
1.5th percentile
VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | avi_load_balancer | — | — |
| vmware | avi_load_balancer | 22.1.1 – 22.1.7 | — |
| vmware | avi_load_balancer | 30.1.1 – 30.2.6 | — |
| vmware | avi_load_balancer | 31.1.1 – 31.2.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
VMware Avi Load Balancer up to 22.1.7/30.2.6/31.2.2/32.1.1 Local Privilege Escalation (EUVD-2026-45363)
vuldb·2026-07-18·CVSS 7.8
CVE-2026-47868 [HIGH] VMware Avi Load Balancer up to 22.1.7/30.2.6/31.2.2/32.1.1 Local Privilege Escalation (EUVD-2026-45363)
A vulnerability was found in VMware Avi Load Balancer up to 22.1.7/30.2.6/31.2.2/32.1.1. It has been classified as very critical. The impacted element is an unknown function. This manipulation causes Local Privilege Escalation.
This vulnerability is registered as CVE-2026-47868. The attack needs to be launched locally. No exploit is available.
GHSA
VMware Avi Load Balancer contains a local privilege escalation vulnerability.
ghsa_unreviewed·2026-07-18
CVE-2026-47868 [HIGH] CWE-269 VMware Avi Load Balancer contains a local privilege escalation vulnerability.
VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-18
Published