GPU VulnDB

Database/Control plane, storage & DevOps

VMware Avi Load Balancer: authenticated user can inject and execute code on the Controller

CVE-2026-47869Control plane, storage & DevOpscurated

Impact

A user who already holds credentials on the Avi Controller can inject code and have it execute, turning any low-privileged operator or service account into control of the load-balancer control plane. That crosses the line the tenant model depends on: read-only or per-tenant Avi accounts are commonly handed out to application teams, and this flaw makes such an account equivalent to Controller administrator. For a GPU cluster that publishes model endpoints through Avi, the holder can then redirect or terminate traffic for pools they were never granted. The record gives no detail on the injection sink.

Who can reach it

Authenticated network access to the Avi Controller - any account that can log in to the Controller API or UI.

What to do

Upgrade the Controller to 32.1.2, 31.2.2-2p3, or 30.2.7 depending on your train (22.1.x moves to 30.2.7). Same upgrade as the rest of this advisory, so one Controller maintenance window covers all four. In the meantime, audit and prune Avi Controller accounts, especially shared or delegated tenant logins.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.