VMware Avi Load Balancer Authorization Bypass Vulnerability

Vulnerability

An authorization bypass vulnerability has been identified in VMware Avi Load Balancer. This vulnerability allows a malicious actor on the network to access a limited subset of the Avi Control Plane without proper authorization. The issue is present in VMware Avi Load Balancer versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7, with version 32.1.1 being the only version currently available that is not vulnerable.

Impact

Exploitation of this vulnerability could lead to unauthorized access to certain areas of the Avi Control Plane, potentially allowing for further actions or exploits within that environment.

Remediation

Users can upgrade to VMware Avi Load Balancer version 32.1.2, 31.2.2-2p3, or 30.2.7. For those on version 22.1.x, an upgrade to at least 30.2.7 is required.

Added: Jul 18, 2026, 9:23 AM
Updated: Jul 18, 2026, 9:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
7.4
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.