Vmware Avi Load Balancer vulnerabilities
8 known vulnerabilities affecting vmware/avi_load_balancer.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-47865P2CRITICALCVSS 9.8≥ 31.1.1, ≤ 31.2.2≥ 30.1.1, ≤ 30.2.6+1 more2026-07-18
CVE-2026-47865 [CRITICAL] CWE-287 CVE-2026-47865: VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with netw
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.
Affected versions:
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2026-47867P2HIGHCVSS 8.7v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47867 [HIGH] CWE-94 CVE-2026-47867: VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with netwo
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2026-47869P3HIGHCVSS 8.7v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47869 [HIGH] CWE-94 CVE-2026-47869: VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated u
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2026-47871P3HIGHCVSS 8.8v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47871 [HIGH] CWE-22 CVE-2026-47871: VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation
VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2026-47866P3HIGHCVSS 8.3v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47866 [HIGH] CWE-863 CVE-2026-47866: VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the ne
VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.
nvd
CVE-2026-47868P3HIGHCVSS 7.8v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47868 [HIGH] CWE-269 CVE-2026-47868: VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with
VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2026-47870P3HIGHCVSS 7.1v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47870 [HIGH] CWE-269 CVE-2026-47870: VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated us
VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2025-41233P3MEDIUMCVSS 6.8v30.1.1v30.1.2+3 more2025-06-12
CVE-2025-41233 [MEDIUM] CWE-89 CVE-2025-41233: Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability.
Description:
VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the Moderate severity range https://www.broadcom.com/support/vmware-services/security-response with a maximum CVSSv3 base score of 6.8 https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR
nvd