Breaking
SecurityDeveloping Story

Critical Auth Bypass Found in VMware Avi

A critical authentication bypass flaw in VMware Avi Load Balancer has been disclosed, requiring immediate attention to specific versions.

··1 month ago·1 min read
person in black long sleeve shirt using macbook pro
Photo by Towfiqu barbhuiya on Unsplash

A severe security vulnerability has been identified within the VMware Avi Load Balancer, presenting a significant risk to affected installations. The flaw involves a breakdown in the system's authentication process, allowing unauthorized actors with specific network access to reach the platform's control plane.

Understanding the Authentication Vulnerability

The issue, officially tracked under CVE-2026-47865, stems from an authentication bypass vulnerability. By exploiting this weakness, a malicious user who has gained network access can potentially interact with the Avi Control plane, effectively circumventing the security checks typically required to establish a session or interact with administrative functions.

Scope of Affected Software Versions

The vulnerability impacts a range of software versions, with specific release paths requiring targeted updates to remediate the risk. The following versions are listed as affected by the vulnerability:

  • 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
  • 30.1.1 through 30.2.6 (fixed in 30.2.7)
  • 22.1.1 through 22.1.7 (fixed in 30.2.7)

Evaluating Technical Severity

The security implications of this bug are categorized as critical. The assessment provided by the associated advisory highlights the severity level, assigning it a CVSS 9.8 score. This classification reflects the ease with which a user with network access might leverage the bypass to reach the control plane.

Implications for Infrastructure Security

For organizations deploying the VMware Avi Load Balancer, the disclosure necessitates a review of existing software versions against the provided patch list. Because the vulnerability allows for a bypass of the authentication mechanism, the primary concern for system administrators involves the potential for unauthorized access to the control plane, provided the attacker already possesses the necessary network access to interact with the device.

#vmware#cve-2026-47865#authentication bypass#load balancer

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories