general · MITRE
VMware Avi Load Balancer contains an authorization bypass vulnerability allowing network-based actors to access a limited subset of the Avi Control Plane without proper authorization. According to the NVD entry, affected versions include 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7, with fixes available in versions 32.1.2, 31.2.2-2p3, 30.2.7, and later. VMware has assigned a CVSS 3.1 score of 8.3 (HIGH) to this weakness, classified as CWE-863 (Incorrect Authorization).
Defense contractors and regulated organizations relying on Avi load balancers for network infrastructure should inventory their deployments and prioritize patching, particularly if handling controlled unclassified information (CUI) or subject to CMMC requirements. SaaS platforms and healthcare providers using Avi for traffic management face potential exposure of configuration and control-plane data; SOC2 Type II audits typically require documented patching and change-control processes for such infrastructure. An Omniware engagement can help assess your load-balancer footprint, verify patch status, and validate that compensating access controls meet your compliance baseline.
Source: MITRE National Vulnerability Database (NVD) - https://nvd.nist.gov/vuln/detail/CVE-2026-47866
Source: MITRE
All briefings