CVE-2026-47865
Analyzed Analyzed - Analysis Complete

Authentication Bypass in VMware Avi Load Balancer

Vulnerability report for CVE-2026-47865, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-18

Last updated on: 2026-08-20

Assigner: VMware

Description

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-18
Last Modified
2026-08-20
Generated
2026-08-27
AI Q&A
2026-07-18
EPSS Evaluated
2026-08-26
NVD
EUVD

Affected Vendors & Products

Showing 18 associated CPEs
Vendor Product Version / Range
broadcom vmware_avi_load_balancer 31.2.2
broadcom vmware_avi_load_balancer 31.2.2
broadcom vmware_avi_load_balancer 31.2.2
broadcom vmware_avi_load_balancer From 30.1.1 (inc) to 30.2.7 (exc)
broadcom vmware_avi_load_balancer From 31.1.1 (inc) to 31.2.2 (exc)
broadcom vmware_avi_load_balancer 32.1.1
broadcom vmware_avi_load_balancer From 22.1.1 (inc) to 22.1.7 (exc)
broadcom vmware_avi_load_balancer 22.1.7
broadcom vmware_avi_load_balancer 22.1.7
broadcom vmware_avi_load_balancer 22.1.7
broadcom vmware_avi_load_balancer 22.1.7
broadcom vmware_avi_load_balancer 22.1.7
broadcom vmware_avi_load_balancer 22.1.7
broadcom vmware_avi_load_balancer 22.1.7
broadcom vmware_avi_load_balancer 22.1.7
broadcom vmware_avi_load_balancer 22.1.7
broadcom vmware_avi_load_balancer 22.1.7
broadcom vmware_avi_load_balancer 22.1.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

VMware Avi Load Balancer has an authentication bypass vulnerability. This means a malicious user with network access could bypass the authentication mechanism and gain unauthorized access to the Avi Control plane.

Detection Guidance

This vulnerability allows bypassing authentication in VMware Avi Load Balancer. To detect it, check the version of your Avi Load Balancer. If it is between 31.1.1-31.2.2, 30.1.1-30.2.6, or 22.1.1-22.1.7, it is vulnerable. Verify if the version is below the fixed versions (31.2.2-2p3, 30.2.7, or 30.2.7 respectively).

Impact Analysis

An attacker could exploit this to take control of the load balancer, potentially intercepting or manipulating network traffic, leading to data breaches or service disruptions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for GDPR, HIPAA, and other regulations that mandate strict access controls and data protection.

Mitigation Strategies

Immediately upgrade affected VMware Avi Load Balancer versions to the fixed releases: 31.2.2-2p3, 30.2.7, or 22.1.7. Isolate the system from untrusted networks if patching is delayed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47865. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart