Database/Control plane, storage & DevOps
VMware Avi Load Balancer: authentication bypass grants network access to the Avi control plane
Impact
A user with network access to the Avi Controller can bypass authentication and reach the control plane outright. The Avi Controller programs the service engines that front application traffic, so control there means retargeting or intercepting traffic for every virtual service it manages, harvesting the TLS material and pool configuration it holds, and pushing configuration to data-plane engines. In a datacenter that fronts inference endpoints or cluster APIs with Avi, this is a position above the workloads rather than inside one - the compromise is felt by every tenant behind the load balancer, not just the attacker's own. Broadcom rates it 9.8 with no privileges and no user interaction.
Who can reach it
Anyone with network access to the Avi Controller. No valid credentials needed, so exposure is determined entirely by who can route to the management interface.
What to do
Upgrade per Broadcom's advisory: 31.1.1-31.2.2 is fixed in 31.2.2-2p3, and both the 30.1.1-30.2.6 and 22.1.1-22.1.7 lines are fixed in 30.2.7. This is a controller upgrade - service engines keep forwarding traffic during a controller outage, but configuration changes and scaling pause for the window, and a clustered controller should be upgraded following Broadcom's node-by-node procedure. Confirm the management interface is not reachable from tenant networks either way.
References
Related entries
- rclone (rcd remote control server): An unauthenticated request to the rclone remote-control server instantiates aCVE-2026-49980 · rclone (rcd remote control server)Critical
- Proxmox VE (libpve-storage-perl XXE): XML external entity injection in the Proxmox storage library, reachableCVE-2026-51080 · Proxmox VE (libpve-storage-perl XXE)Critical
- Linux NFS server (nfsd, SECINFO_NO_NAME decode): A truncated SECINFO_NO_NAME operation leaves sin_exp uninitialized andCVE-2026-53398 · Linux NFS server (nfsd, SECINFO_NO_NAME decode)Critical
- Airflow FAB provider: Azure AD login accepted unsigned ID tokens, allowing login as AdminCVE-2026-59243 · Apache Airflow FAB auth manager (Azure AD OAuth ID token validation)Critical
- VMware vCenter (VMware Directory Service authentication bypass): An unauthenticated attacker with network accessCVE-2026-59309 · VMware vCenter (VMware Directory Service authentication bypass)Critical
- VMware vCenter (Syslog server directory traversal to RCE): Directory traversal in the vCenter syslog server lettingCVE-2026-59310 · VMware vCenter (Syslog server directory traversal to RCE)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.