
[CIVN-2026-0370] Multiple Vulnerabilities in VMware Avi Load Balancer
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in VMware Avi Load Balancer
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
VMware Avi Load Balancer version 31.1.1 – 31.2.2
VMware Avi Load Balancer version 30.1.1 – 30.2.6
VMware Avi Load Balancer version 22.1.1 – 22.1.7
VMware Avi Load Balancer version 32.1.1
Overview
Multiple vulnerabilities have been reported in VMware Avi Load Balancer, which could allow an attacker to gain unauthorised access, escalate privileges, execute arbitrary code, and gain access to sensitive information on the targeted system.
Target Audience:
Enterprises and large organisations, cloud service providers and industries with IT environments utilizing VMware Avi Load Balancer.
Risk Assessment:
Risk of full system compromise, sensitive information disclosure and lateral movement.
Impact Assessment:
Potential for local privilege escalation, disclosure of sensitive information and unauthorised access.
Description
VMware Avi Load Balancer is a software-defined, multi-cloud application delivery controller that provides elastic load balancing, application security (WAF), and observability for containerized, virtualised, and bare-metal workloads.
Multiple vulnerabilities exist in VMware Avi Load Balancer due to improper authentication, insufficient input validation, improper privilege management and file path validation issues. An attacker may exploit these vulnerabilities by sending specially crafted requests.
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorised access, escalate privileges, execute arbitrary code, and gain access to sensitive information on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926
Vendor Information
VMware
https://support.broadcom.com/web/ecx/security-advisory
References
VMware
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926
CVE Name
CVE-2026-47865
CVE-2026-47866
CVE-2026-47867
CVE-2026-47868
CVE-2026-47869
CVE-2026-47870
CVE-2026-47871
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpfiOkACgkQ3jCgcSdc
ys+oxA//VFa5Ue2rqmUEIYzcnR9JZlzZSHaEl3pPaQKnjGVDqAht2GI8PN8J0Bpx
iMr01WhhOurT28txm9qVJ20cjNxV0UyMBki5ICOZovSwFiLSFq2NZA1MFQKc17Xr
Sc9wg5P3sS3FOwpTxMh240ZCrHAkwh9yQNU5I7RGhECR2eMMlicLghzfSdy4BBTr
VioCa+c4bxFXja7ypk/WNwLI++QNyOt/khEEJPhwZXcIwuFiwnRLWpXFF5HSKxAd
o+AI0wc5F2N0M7x2udUEDLX8pA7OfVnc7tTkLkguYvX/8DPsfc25NqoXuWg6RWaH
c9eI//kf2WaZ+KBmpsOMzboj3oGIp9l9oR1vtxjhn581GI0TkgBgrjNGdh2FWOrj
+Iz14ErxRZ6185p2LQJ3tkaRo34tVa0ENSzP94dbFT/jd4fMipkDMpv4R0tlDpJF
vsQfI9IcN2bmVyD5bvO14ML0YbphvzLcySCPzkMH2KgxlT48zKidgPM4qiaqde7H
AtIRocsHgHVEo2bfEaiffLvMb5xumJprLN0o7desHwSp8wyOChV0Mcpu/nUp2mtt
Dth0TUsf3Wtl9qqwhpQ954tuPIhov4Uz6V0ueFrEZxUDbx468062TdixMcHlrf8d
4aoBQsf69OMlcsQDoEZpJNuPVoxhUJfyZUg7oUdMQ5eitoGT3dI=
=KjD4
—–END PGP SIGNATURE—–


