Critical Auth Bypass in VMware Avi Load
A critical authentication bypass vulnerability has been identified in VMware Avi Load Balancer, documented as CVE-2026-47865.
Security researchers have identified a vulnerability within the VMware Avi Load Balancer that permits unauthorized access to the system. This flaw, tracked as CVE-2026-47865, allows an individual with network access to circumvent the established authentication protocols of the Avi Control plane.
Vulnerability Scope and Severity
The issue has been classified as critical, carrying a CVSS score of 9.8. Because the vulnerability exists within the authentication mechanism itself, it presents a significant risk to the integrity of the affected load balancer deployments. The technical details confirm that the bypass specifically targets the Avi Control plane interface.
Affected Product Versions
The vulnerability impacts several iterations of the software, spanning different version branches. Users must verify their current build status against the following affected ranges to determine if they are exposed:
- Version 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
- Version 30.1.1 through 30.2.6 (fixed in 30.2.7)
- Version 22.1.1 through 22.1.7 (fixed in 30.2.7)
Managing System Security Risks
For organizations operating these specific versions, the primary path to remediation involves updating to the designated fixed versions provided by the vendor. The vulnerability exclusively concerns the ability for a user with network access to reach the control plane without meeting standard authentication requirements. Staying current with these version releases is the only documented method for addressing this specific flaw.
Implications for Infrastructure Security
The presence of a 9.8 CVSS-rated vulnerability within a core infrastructure component like a load balancer necessitates immediate attention from administrative teams. Because the flaw relates to the control plane, the security of the broader management architecture depends on the application of the provided fixes. Organizations should prioritize inventory checks to identify instances of the vulnerable software versions listed in the advisory.
Sources
- GitHub Security Advisories Original source
Continue Reading
Faronics Deploy Abused in ScreenConnect Attacks
Hackers exploit Faronics Deploy to enroll victims and install ScreenConnect, researchers report.
Palo Alto Networks Buys Console for Agentic Security
Palo Alto Networks acquires Console, an AI-native agentic workflow platform, to deepen Cortex's autonomous security capabilities.
Meta's $17B Settlement
EFF says Meta's proposed $17 billion settlement fails to protect teens and could harm all users' privacy.