cbcvebase.

Vmware Avi Load Balancer vulnerabilities

8 known vulnerabilities affecting vmware/avi_load_balancer.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-47865P2CRITICALCVSS 9.8≥ 31.1.1, ≤ 31.2.2≥ 30.1.1, ≤ 30.2.6+1 more2026-07-18
CVE-2026-47865 [CRITICAL] CWE-287 CVE-2026-47865: VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with netw VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2026-47867P2HIGHCVSS 8.7v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47867 [HIGH] CWE-94 CVE-2026-47867: VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with netwo VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2026-47869P3HIGHCVSS 8.7v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47869 [HIGH] CWE-94 CVE-2026-47869: VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated u VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2026-47871P3HIGHCVSS 8.8v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47871 [HIGH] CWE-22 CVE-2026-47871: VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2026-47866P3HIGHCVSS 8.3v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47866 [HIGH] CWE-863 CVE-2026-47866: VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the ne VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.
nvd
CVE-2026-47868P3HIGHCVSS 7.8v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47868 [HIGH] CWE-269 CVE-2026-47868: VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2026-47870P3HIGHCVSS 7.1v32.1.1≥ 31.1.1, ≤ 31.2.2+2 more2026-07-18
CVE-2026-47870 [HIGH] CWE-269 CVE-2026-47870: VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated us VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd
CVE-2025-41233P3MEDIUMCVSS 6.8v30.1.1v30.1.2+3 more2025-06-12
CVE-2025-41233 [MEDIUM] CWE-89 CVE-2025-41233: Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the Moderate severity range https://www.broadcom.com/support/vmware-services/security-response with a maximum CVSSv3 base score of 6.8 https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR
nvd
Vmware Avi Load Balancer vulnerabilities | cvebase