[CIVN-2026-0370] Multiple Vulnerabilities in VMware Avi Load Balancer

By Published On: July 21, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in VMware Avi Load Balancer


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


VMware Avi Load Balancer version 31.1.1 – 31.2.2

VMware Avi Load Balancer version 30.1.1 – 30.2.6

VMware Avi Load Balancer version 22.1.1 – 22.1.7

VMware Avi Load Balancer version 32.1.1

Overview


Multiple vulnerabilities have been reported in VMware Avi Load Balancer, which could allow an attacker to gain unauthorised access, escalate privileges, execute arbitrary code, and gain access to sensitive information on the targeted system.


Target Audience:

Enterprises and large organisations, cloud service providers and industries with IT environments utilizing VMware Avi Load Balancer.


Risk Assessment:

Risk of full system compromise, sensitive information disclosure and lateral movement.


Impact Assessment:

Potential for local privilege escalation, disclosure of sensitive information and unauthorised access.


Description


VMware Avi Load Balancer is a software-defined, multi-cloud application delivery controller that provides elastic load balancing, application security (WAF), and observability for containerized, virtualised, and bare-metal workloads.


Multiple vulnerabilities exist in VMware Avi Load Balancer due to improper authentication, insufficient input validation, improper privilege management and file path validation issues. An attacker may exploit these vulnerabilities by sending specially crafted requests.


Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorised access, escalate privileges, execute arbitrary code, and gain access to sensitive information on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926



Vendor Information


VMware

https://support.broadcom.com/web/ecx/security-advisory


References


VMware

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926


CVE Name

CVE-2026-47865

CVE-2026-47866

CVE-2026-47867

CVE-2026-47868

CVE-2026-47869

CVE-2026-47870

CVE-2026-47871




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpfiOkACgkQ3jCgcSdc

ys+oxA//VFa5Ue2rqmUEIYzcnR9JZlzZSHaEl3pPaQKnjGVDqAht2GI8PN8J0Bpx

iMr01WhhOurT28txm9qVJ20cjNxV0UyMBki5ICOZovSwFiLSFq2NZA1MFQKc17Xr

Sc9wg5P3sS3FOwpTxMh240ZCrHAkwh9yQNU5I7RGhECR2eMMlicLghzfSdy4BBTr

VioCa+c4bxFXja7ypk/WNwLI++QNyOt/khEEJPhwZXcIwuFiwnRLWpXFF5HSKxAd

o+AI0wc5F2N0M7x2udUEDLX8pA7OfVnc7tTkLkguYvX/8DPsfc25NqoXuWg6RWaH

c9eI//kf2WaZ+KBmpsOMzboj3oGIp9l9oR1vtxjhn581GI0TkgBgrjNGdh2FWOrj

+Iz14ErxRZ6185p2LQJ3tkaRo34tVa0ENSzP94dbFT/jd4fMipkDMpv4R0tlDpJF

vsQfI9IcN2bmVyD5bvO14ML0YbphvzLcySCPzkMH2KgxlT48zKidgPM4qiaqde7H

AtIRocsHgHVEo2bfEaiffLvMb5xumJprLN0o7desHwSp8wyOChV0Mcpu/nUp2mtt

Dth0TUsf3Wtl9qqwhpQ954tuPIhov4Uz6V0ueFrEZxUDbx468062TdixMcHlrf8d

4aoBQsf69OMlcsQDoEZpJNuPVoxhUJfyZUg7oUdMQ5eitoGT3dI=

=KjD4

—–END PGP SIGNATURE—–

Share this article