CVE-2026-47865 Details
Description
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
A critical authentication bypass vulnerability has been identified in VMware Avi Load Balancer versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7. This vulnerability allows a malicious user with network access to bypass authentication and access the Avi Control plane. The issue has been evaluated with a CVSSv3 base score of 9.8, indicating its critical severity.
Users can upgrade to VMware Avi Load Balancer versions 31.2.2-2p3, 30.2.7, or 32.1.2 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| broadcom vmware avi load balancer | >= 22.1.1, < 22.1.7 >= 30.1.1, < 30.2.7 >= 31.1.1, < 31.2.2 22.1.7 - 22.1.7 2p10 22.1.7 2p11 22.1.7 2p2 22.1.7 2p3 22.1.7 2p4 22.1.7 2p5 22.1.7 2p6 22.1.7 2p7 22.1.7 2p8 22.1.7 2p9 31.2.2 - 31.2.2 2p1 31.2.2 2p2 32.1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 20, 2026 | Initial Analysis | [email protected] |
| Jul 23, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 18, 2026 | New CVE Received | [email protected] |