CVE-2026-47867 Details
Description
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
A remote code execution vulnerability has been identified in VMware Avi Load Balancer. This issue allows a malicious user with network access to the Avi Control Plane to execute code remotely. The vulnerability is present in versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7, with version 32.1.1 being the only exception. The vulnerability arises from flaws in the application's handling of network requests, which can be exploited to inject and execute arbitrary code on the server.
Users can upgrade to VMware Avi Load Balancer version 32.1.2, 31.2.2-2p3, or 30.2.7. For version 22.1.x, an upgrade to at least 30.2.7 is required.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| broadcom vmware avi load balancer | >= 22.1.1, <= 22.1.7 >= 30.1.1, < 30.2.7 >= 31.1.1, < 31.2.2 31.2.2 - 31.2.2 2p1 31.2.2 2p2 32.1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 20, 2026 | Initial Analysis | [email protected] |
| Jul 23, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 18, 2026 | New CVE Received | [email protected] |