Database/Control plane, storage & DevOps
VMware Avi Load Balancer: directory traversal through weak file path validation
Impact
Weak file path validation lets an authenticated network user traverse outside the intended directory on the Avi Controller. In practice that means reading or touching files the Controller account should not reach - configuration, certificates or logs held by the appliance. It is the least severe of the four issues in this advisory, but it lands on the same box, and it is a useful stepping stone toward the code-execution flaws published with it. The record does not say whether the traversal is read-only or also permits writes.
Who can reach it
Authenticated network user of the Avi Controller.
What to do
Upgrade the Controller to 32.1.2, 31.2.2-2p3, or 30.2.7 as appropriate for your train (22.1.x moves to 30.2.7). Fixed by the same releases as CVE-2026-47867, -47869 and -47870, so treat all four as one Controller upgrade.
References
Related entries
- Apache CloudStack: metalink template registration gives a tenant root on the KVM hypervisor hostCVE-2026-50112 · Apache CloudStack (template registration via metalink and direct download to the KVM agent)High
- Jenkins: attacker-controlled config.xml deserialization allows user impersonation and code executionCVE-2026-53435 · Jenkins controller (config.xml deserialization of arbitrary core and plugin types)High
- Apache Airflow: executor_config deserialization imports arbitrary callables in scheduler and API serverCVE-2026-58076 · Apache Airflow serialization layer (exception branch reached via operator executor_config)High
- rclone (serve restic --private-repos): --private-repos is meant to confine each authenticated user to their ownCVE-2026-59733 · rclone (serve restic --private-repos)High
- Red Hat ACM: ManagedClusterAddOn annotation overrides governance-policy image, giving cluster-admin execCVE-2026-66793 · Red Hat Advanced Cluster Management governance-policy-addon-controllerHigh
- Apache Airflow: Callback deserialization in the scheduler timeout sweep imports Dag-author-chosen modulesCVE-2026-67587 · Apache Airflow Task SDK Callback deserialization (task instance next_kwargs)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.