Database/Control plane, storage & DevOps
VMware Avi Load Balancer: directory traversal through weak file path validation
Impact
Weak file path validation lets an authenticated network user traverse outside the intended directory on the Avi Controller. In practice that means reading or touching files the Controller account should not reach - configuration, certificates or logs held by the appliance. It is the least severe of the four issues in this advisory, but it lands on the same box, and it is a useful stepping stone toward the code-execution flaws published with it. The record does not say whether the traversal is read-only or also permits writes.
Who can reach it
Authenticated network user of the Avi Controller.
What to do
Upgrade the Controller to 32.1.2, 31.2.2-2p3, or 30.2.7 as appropriate for your train (22.1.x moves to 30.2.7). Fixed by the same releases as CVE-2026-47867, -47869 and -47870, so treat all four as one Controller upgrade.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.