Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-47865

CVE-2026-47865: VMware Avi Load Balancer Auth Bypass Flaw

CVE-2026-47865 is an authentication bypass vulnerability in VMware Avi Load Balancer that allows attackers with network access to bypass authentication and access the Avi Control plane. This article covers affected versions, impact, and mitigation strategies.

Published:

CVE-2026-47865 Overview

CVE-2026-47865 is an authentication bypass vulnerability in VMware Avi Load Balancer. A malicious user with network access to the appliance can reach the Avi Control plane by circumventing the authentication mechanism. The flaw is tracked under CWE-287 (Improper Authentication) and carries a CVSS 3.1 base score of 9.8.

Broadcom published Security Advisory #37926 with fixed builds for each supported branch. The vulnerability affects Avi Load Balancer versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7.

Critical Impact

An unauthenticated network-based attacker can gain access to the Avi Control plane, exposing load balancer configuration, traffic policies, and backend services to complete compromise.

Affected Products

  • VMware Avi Load Balancer 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
  • VMware Avi Load Balancer 30.1.1 through 30.2.6 (fixed in 30.2.7)
  • VMware Avi Load Balancer 22.1.1 through 22.1.7 (fixed in 30.2.7)

Discovery Timeline

  • 2026-07-18 - CVE-2026-47865 published to NVD
  • 2026-07-23 - Last updated in NVD database

Technical Details for CVE-2026-47865

Vulnerability Analysis

CVE-2026-47865 is an authentication bypass affecting the VMware Avi Load Balancer Control plane. The Control plane exposes management APIs and configuration interfaces used to program the data plane, define virtual services, and orchestrate application delivery. An attacker who reaches the Control plane over the network can bypass the authentication logic and act as a privileged user without valid credentials.

The vulnerability is categorized as [CWE-287] Improper Authentication, indicating the authentication routine can be circumvented rather than requiring credential theft or brute force. Because the flaw is network-reachable with low attack complexity, no privileges, and no user interaction, it is trivially exploitable by any attacker with access to the management interface.

The current EPSS probability of 0.874% reflects moderate near-term exploitation likelihood. Broadcom does not report exploitation in the wild, and the vulnerability is not listed on the CISA KEV catalog.

Root Cause

The root cause is a defect in the authentication mechanism protecting the Avi Control plane. Broadcom's advisory does not disclose the specific code path, but the CWE-287 classification indicates the authentication check can be bypassed under attacker-controlled conditions rather than enforced consistently on all privileged endpoints.

Attack Vector

Exploitation requires network access to the Avi Load Balancer management interface. An attacker sends crafted requests to the Control plane that evade the authentication decision, obtaining access equivalent to an authenticated administrator. This grants control over load balancer configuration, TLS certificates, backend pool members, and traffic policies.

No verified proof-of-concept code is public. Refer to the Broadcom Security Advisory #37926 for vendor technical details.

Detection Methods for CVE-2026-47865

Indicators of Compromise

  • Unexpected administrative API calls to Avi Control plane endpoints from unfamiliar source IP addresses.
  • New or modified virtual service, pool, or SSL profile configurations without a matching change ticket.
  • Successful management-plane sessions where no corresponding authentication event was logged.
  • Creation of new administrative users, tokens, or API keys on the Avi controller.

Detection Strategies

  • Compare Avi controller audit logs against your change management system to surface configuration drift.
  • Alert on any authenticated action lacking a preceding successful login event in the same session context.
  • Monitor for anomalous HTTP request patterns targeting /api/ paths on the Avi Control plane from non-management networks.
  • Baseline expected administrative source IP ranges and alert on deviations.

Monitoring Recommendations

  • Forward Avi controller audit and access logs to a centralized SIEM for correlation with network telemetry.
  • Track outbound connections from Avi controllers, as post-exploitation activity may include lateral movement or data exfiltration.
  • Enable packet capture on management VLANs during incident response to preserve request payloads.

How to Mitigate CVE-2026-47865

Immediate Actions Required

  • Upgrade Avi Load Balancer to 31.2.2-2p3, 30.2.7, or the corresponding fixed build for the 22.1.x branch.
  • Restrict Control plane network exposure to trusted management networks only, blocking access from user and internet-facing segments.
  • Rotate administrative credentials, API tokens, and TLS keys after patching if compromise is suspected.
  • Review audit logs for unauthorized configuration changes made prior to patching.

Patch Information

Broadcom released fixed builds documented in Security Advisory #37926. Version 31.2.2-2p3 resolves the issue for the 31.x branch. Version 30.2.7 resolves the issue for both the 30.x branch and the 22.1.x branch, which is remediated by upgrading to the 30.2.7 release.

Workarounds

  • No vendor-supplied workaround replaces patching; apply fixed builds as the primary remediation.
  • Place the Avi Control plane behind a jump host or bastion with strong authentication and IP allow-listing.
  • Enforce network segmentation so only authorized administrator workstations can reach the management interface.
  • Enable and monitor detailed audit logging on the Avi controller until upgrades are completed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.