Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
8.3
CVE-2026-47866
vmware · avi load balancer

VMware Avi Load Balancer Authorization Bypass Vulnerability

Description

VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

Affected Products

VendorProductVersions
vmwareavi load balancer32.1.1, 31.1.1, 30.1.1, 22.1.1

References

  • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926

Related News (1 articles)

Tier C
VulDB71d ago
CVE-2026-47866 | VMware Avi Load Balancer up to 22.1.7/30.2.6/31.2.2/32.1.1 Control Plane authorization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
CWECWE-863
PublishedJul 18, 2026
Last enriched71d agov2
Trending Score0
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59309EXPKEV
vCenter authentication-bypass vulnerability
Trending: 66
CRITICALCVE-2026-59310EXPKEV
vCenter directory-traversal vulnerability
Trending: 39
MEDIUMCVE-2026-59296
Micrometer StatsD and Logging meter registries line-protocol and log injection vulnerability
Trending: 5
MEDIUMCVE-2026-59355
Spring Authorization Server: Open Redirect via request_uri parameter
Trending: 1
MEDIUMCVE-2026-59323
Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 18, 2026
Discovered by ZDM
Jul 18, 2026
Updated: severity, cvssEstimate
Jul 18, 2026

Version History

v2
Last enriched 71d ago
v2Tier C71d ago

Severity upgraded from HIGH to CRITICAL based on article classification as 'very critical'; CVSS estimate adjusted accordingly from 8.3 to 9.0

severitycvssEstimate
via VulDB
v171d ago

Initial creation