VMware Patches Critical Avi Load Balancer Vulnerabilities

Broadcom has released security updates to address seven vulnerabilities in VMware Avi Load Balancer, a software-defined platform used for load balancing and application security in hybrid and multi-cloud environments. These vulnerabilities include authentication bypass, remote code execution, privilege escalation, and directory traversal issues.

Details of the Vulnerabilities

The most critical of these is CVE-2026-47865, an authentication bypass vulnerability with a CVSS score of 9.8. This flaw allows attackers with network access to the Avi control plane to bypass authentication mechanisms, potentially leading to unauthorized access and control over the system. Additionally, CVE-2026-47867 and CVE-2026-47869 are remote code execution vulnerabilities that could enable attackers to execute arbitrary code on the affected systems. CVE-2026-47868 and CVE-2026-47870 are privilege escalation vulnerabilities that could allow attackers to gain elevated privileges. CVE-2026-47871 is a directory traversal vulnerability that could enable attackers to access restricted files outside a server’s root folder.

Affected Versions and Mitigation

The vulnerabilities affect the following versions of VMware Avi Load Balancer:

  • 22.1.x, all versions
  • 30.2.x, versions prior to 30.2.7
  • 31.1.x, versions prior to 31.2.2-2p3
  • 32.1.x, versions prior to 32.1.2

Users are strongly advised to upgrade to the latest version, VMware Avi Load Balancer 32.1.2, to mitigate these vulnerabilities. Broadcom has not reported any in-the-wild exploitation of these bugs as of now.

Given the critical nature of these vulnerabilities, organizations using VMware Avi Load Balancer should prioritize applying these patches to prevent potential exploitation. This incident underscores the importance of regular security assessments and timely updates to maintain the integrity and security of enterprise systems.