GPU VulnDB

Database/Control plane, storage & DevOps

VMware Avi Load Balancer: authenticated privilege escalation leading to remote code execution

CVE-2026-47870Control plane, storage & DevOpscurated

Impact

An authenticated Avi user can escalate privilege to the point of executing code remotely on the Controller. The practical consequence is the same as the other Controller flaws in this advisory: whoever holds a modest Avi login ends up owning the device that fronts every published service. Where inference endpoints for several tenants share one Avi instance, that is a tenancy boundary failure, and the Controller also stores the certificates and pool configuration for those endpoints. No further technical detail is published in the record.

Who can reach it

Authenticated network access to the Avi Controller. No pre-auth path is described.

What to do

Upgrade the Controller to 32.1.2, 31.2.2-2p3, or 30.2.7 for your train (22.1.x moves to 30.2.7) - a Controller software upgrade and restart. This is the same fix that closes the other three issues published alongside it.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.