general · MITRE
VMware Avi Load Balancer contains an authentication bypass vulnerability that allows a malicious user with network access to access the Avi Control plane without proper credentials. The vulnerability affects versions 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (fixed in 30.2.7). VMware has assigned a CVSS 3.1 score of 9.8 (Critical) with a network-based attack vector requiring no privilege or user interaction.
Organizations relying on Avi Load Balancer for traffic management and security must prioritize patching, especially those handling sensitive workloads. Defense contractors using Avi in CUI-processing environments should ensure control plane isolation and verify patch deployment to prevent unauthorized access to infrastructure controls. SaaS and healthcare teams with Avi deployments should evaluate their SOC 2 and HIPAA control effectiveness around access logging and network segmentation; authentication bypass gaps at the load balancer tier can undermine downstream compliance assertions. An Omniware engagement can scope the risk exposure and remediation prioritization specific to your environment.
Source: MITRE / NIST National Vulnerability Database - https://nvd.nist.gov/vuln/detail/CVE-2026-47865
Source: MITRE
All briefings