VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code.
Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
References
| Link | Resource |
|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-18 09:17
Updated : 2026-08-20 19:18
NVD link : CVE-2026-47869
Mitre link : CVE-2026-47869
CVE.ORG link : CVE-2026-47869
JSON object : View
Products Affected
broadcom
- vmware_avi_load_balancer
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
