Breaking
SecurityDeveloping Story

VMware Avi Auth Bypass Flaw Detailed

A critical authentication bypass vulnerability identified in VMware Avi Load Balancer could allow unauthorized access to the control plane.

··1 month ago·1 min read
Matrix movie still
Photo by Markus Spiske on Unsplash

Security researchers have identified a significant flaw within the VMware Avi Load Balancer, pointing to a vulnerability that enables an authentication bypass. This issue, tracked under the identifier CVE-2026-47865, could permit an attacker with network access to interact with the Avi Control plane.

Vulnerability Scope and Impact

The core of the issue lies in the system's authentication mechanism. By circumventing this verification process, an unauthorized user gains the ability to reach the control plane. The vulnerability has been assigned a CVSS score of 9.8, designating it as a critical security risk within the affected software infrastructure.

Affected Product Version Ranges

The advisory highlights specific software versions that are susceptible to the authentication bypass. Administrators and network operators should verify their current deployments against the following ranges:

  • 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
  • 30.1.1 through 30.2.6 (fixed in 30.2.7)
  • 22.1.1 through 22.1.7 (fixed in 30.2.7)

Mitigation and Remediation Steps

Addressing this security gap requires updating the affected load balancer deployments to the specified patch releases. The fix is integrated into the later versions as listed in the advisory details. Organizations managing these devices must review their patch management cycles to ensure the 31.2.2-2p3 or 30.2.7 versions are deployed where applicable.

Implications for Network Security

The presence of this bypass suggests that internal network perimeters may not provide sufficient protection for the Avi Control plane if the underlying software is unpatched. For security teams, this could mean that prioritizing these updates is necessary to maintain control over the load balancing environment and prevent potential unauthorized interactions with critical management interfaces.

#vmware#cve-2026-47865#authentication-bypass#load-balancer#critical

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories