GPU VulnDB

Database/Control plane, storage & DevOps

VMware Avi Load Balancer: authentication bypass grants network access to the Avi control plane

CVE-2026-47865Control plane, storage & DevOpscurated

Impact

A user with network access to the Avi Controller can bypass authentication and reach the control plane outright. The Avi Controller programs the service engines that front application traffic, so control there means retargeting or intercepting traffic for every virtual service it manages, harvesting the TLS material and pool configuration it holds, and pushing configuration to data-plane engines. In a datacenter that fronts inference endpoints or cluster APIs with Avi, this is a position above the workloads rather than inside one - the compromise is felt by every tenant behind the load balancer, not just the attacker's own. Broadcom rates it 9.8 with no privileges and no user interaction.

Who can reach it

Anyone with network access to the Avi Controller. No valid credentials needed, so exposure is determined entirely by who can route to the management interface.

What to do

Upgrade per Broadcom's advisory: 31.1.1-31.2.2 is fixed in 31.2.2-2p3, and both the 30.1.1-30.2.6 and 22.1.1-22.1.7 lines are fixed in 30.2.7. This is a controller upgrade - service engines keep forwarding traffic during a controller outage, but configuration changes and scaling pause for the window, and a clustered controller should be upgraded following Broadcom's node-by-node procedure. Confirm the management interface is not reachable from tenant networks either way.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.