Database/Control plane, storage & DevOps
VMware Avi Load Balancer: authenticated privilege escalation leading to remote code execution
Impact
An authenticated Avi user can escalate privilege to the point of executing code remotely on the Controller. The practical consequence is the same as the other Controller flaws in this advisory: whoever holds a modest Avi login ends up owning the device that fronts every published service. Where inference endpoints for several tenants share one Avi instance, that is a tenancy boundary failure, and the Controller also stores the certificates and pool configuration for those endpoints. No further technical detail is published in the record.
Who can reach it
Authenticated network access to the Avi Controller. No pre-auth path is described.
What to do
Upgrade the Controller to 32.1.2, 31.2.2-2p3, or 30.2.7 for your train (22.1.x moves to 30.2.7) - a Controller software upgrade and restart. This is the same fix that closes the other three issues published alongside it.
References
Related entries
- VMware Avi Load Balancer: remote code execution on the Avi Controller control planeCVE-2026-47867 · VMware Avi Load Balancer (Controller control plane)High
- VMware Avi Load Balancer: authenticated user can inject and execute code on the ControllerCVE-2026-47869 · VMware Avi Load Balancer (Controller control plane)High
- VMware Avi Load Balancer: directory traversal through weak file path validationCVE-2026-47871 · VMware Avi Load Balancer (Controller file path validation)High
- Apache CloudStack: metalink template registration gives a tenant root on the KVM hypervisor hostCVE-2026-50112 · Apache CloudStack (template registration via metalink and direct download to the KVM agent)High
- Jenkins: attacker-controlled config.xml deserialization allows user impersonation and code executionCVE-2026-53435 · Jenkins controller (config.xml deserialization of arbitrary core and plugin types)High
- Apache Airflow: executor_config deserialization imports arbitrary callables in scheduler and API serverCVE-2026-58076 · Apache Airflow serialization layer (exception branch reached via operator executor_config)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.