Improper Authentication in VMware Avi Load Balancer - CVE-2026-47865

 

Improper Authentication in VMware Avi Load Balancer - CVE-2026-47865

Published: July 14, 2026


Vulnerability identifier: #VU137515
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47865
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication and access the Avi Control plane.

The vulnerability exists due to improper authentication in the authentication mechanism when handling network requests to the Avi Control plane. A remote attacker can send crafted requests to bypass authentication and access the Avi Control plane.


Affected software

VMware Avi Load Balancer

How to mitigate CVE-2026-47865

Install security update from vendor's website.

VMware Avi Load Balancer - addressed in versions 30.2.7, 31.2.2-2-p3, 32.1.2

External References

Related Security Bulletins