VMware Avi Load Balancer Authentication Bypass Vulnerability

Vulnerability

A critical authentication bypass vulnerability has been identified in VMware Avi Load Balancer versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7. This vulnerability allows a malicious user with network access to bypass authentication and access the Avi Control plane. The issue has been evaluated with a CVSSv3 base score of 9.8, indicating its critical severity.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the Avi Control plane, allowing attackers to manipulate load balancing configurations and potentially disrupt application availability.

Remediation

Users can upgrade to VMware Avi Load Balancer versions 31.2.2-2p3, 30.2.7, or 32.1.2 to address this vulnerability.

Added: Jul 18, 2026, 9:24 AM
Updated: Jul 18, 2026, 9:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.