cbcvebase.
CVE-2026-47871
published 2026-07-18

CVE-2026-47871: VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform…

PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.65%
47.4th percentile
VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

Affected

4 ranges
VendorProductVersion rangeFixed in
vmwareavi_load_balancer
vmwareavi_load_balancer22.1.1 – 22.1.7
vmwareavi_load_balancer30.1.1 – 30.2.6
vmwareavi_load_balancer31.1.1 – 31.2.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.