Breaking
SecurityDeveloping Story

Critical Auth Bypass in VMware Avi Load

A critical authentication bypass vulnerability has been identified in VMware Avi Load Balancer, documented as CVE-2026-47865.

··1 month ago·1 min read
red padlock on black computer keyboard
Photo by FlyD on Unsplash

Security researchers have identified a vulnerability within the VMware Avi Load Balancer that permits unauthorized access to the system. This flaw, tracked as CVE-2026-47865, allows an individual with network access to circumvent the established authentication protocols of the Avi Control plane.

Vulnerability Scope and Severity

The issue has been classified as critical, carrying a CVSS score of 9.8. Because the vulnerability exists within the authentication mechanism itself, it presents a significant risk to the integrity of the affected load balancer deployments. The technical details confirm that the bypass specifically targets the Avi Control plane interface.

Affected Product Versions

The vulnerability impacts several iterations of the software, spanning different version branches. Users must verify their current build status against the following affected ranges to determine if they are exposed:

  • Version 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
  • Version 30.1.1 through 30.2.6 (fixed in 30.2.7)
  • Version 22.1.1 through 22.1.7 (fixed in 30.2.7)

Managing System Security Risks

For organizations operating these specific versions, the primary path to remediation involves updating to the designated fixed versions provided by the vendor. The vulnerability exclusively concerns the ability for a user with network access to reach the control plane without meeting standard authentication requirements. Staying current with these version releases is the only documented method for addressing this specific flaw.

Implications for Infrastructure Security

The presence of a 9.8 CVSS-rated vulnerability within a core infrastructure component like a load balancer necessitates immediate attention from administrative teams. Because the flaw relates to the control plane, the security of the broader management architecture depends on the application of the provided fixes. Organizations should prioritize inventory checks to identify instances of the vulnerable software versions listed in the advisory.

#vulnerability#vmware#cve-2026-47865#authentication-bypass#load-balancer

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories