Database/Control plane, storage & DevOps
VMware Avi Load Balancer: local user can escalate to root on the appliance
Impact
A user who already holds a shell on an Avi Controller or Service Engine can run code as root on that appliance. Avi commonly fronts the API and inference endpoints in front of an accelerator fleet and holds the TLS keys and backend pool configuration for them, so root on the controller means the ability to intercept or redirect traffic for every service it publishes, and to change pool membership without touching the fleet itself. The advisory gives no detail on the mechanism beyond local access, so the first practical control is auditing who has appliance shell accounts at all.
Who can reach it
Local user with an existing low-privilege account on the Avi Controller or Service Engine. Authentication required; no network-reachable path stated in the advisory.
What to do
Upgrade per the Broadcom advisory: 32.1.1 to 32.1.2; 31.1.1 through 31.2.2 to 31.2.2-2p3; 30.1.1 through 30.2.6 to 30.2.7; 22.1.1 through 22.1.7 to 30.2.7. This is an appliance upgrade with a controller and Service Engine restart, so plan a traffic-drain window for the SEs rather than treating it as a package bump.
References
Related entries
- Linuxfabrik monitoring plugins: pipe injection in shell_exec escalates a check account to rootCVE-2026-55426 · Linuxfabrik Monitoring Plugins / linuxfabrik-lib (lib.shell.shell_exec)High
- Apache Storm worker-launcher: TOCTOU on the command file gives a tenant root-equivalent container launchCVE-2026-82430 · Apache Storm worker-launcher (setuid-root Docker/OCI worker launch)High
- SonicWall SMA1000: authenticated admin can inject OS commands through the management consoleCVE-2026-83549 · SonicWall SMA1000 appliance (Appliance Management Console, OS command injection)High
- Linux kernel nfsd: module init error path leaves debugfs files pointing into freed module textCVE-2026-89668 · Linux kernel nfsd (debugfs init ordering in init_nfsd)High
- CyberPower PowerPanel managed devices - shared device certificates: Every managed device uses an identical certificateCVE-2024-31410 · CyberPower PowerPanel managed devices - shared device certificatesHigh
- Keycloak: SAML signature scope determined by position, not ReferenceCVE-2024-8698 · KeycloakHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.