SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-47866

HIGH · CVSS 8.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

VMware Avi Load Balancer is susceptible to an authorization bypass vulnerability that allows unauthorized network actors to access a limited subset of the Avi Control Plane. This could lead to potential data exposure or manipulation, posing significant risks to organizations relying on this load balancer for their operations. Organizations using affected versions should prioritize immediate updates to mitigate this high-severity vulnerability.

CVE
CVE-2026-47866
Severity
HIGH
CVSS
8.3
EPSS
0.27%
VMware VMWare

Original NVD Description

VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)