VMware Avi Load Balancer Privilege Escalation Vulnerability Allowing Remote Code Execution

Vulnerability

A privilege escalation vulnerability has been identified in VMware Avi Load Balancer, allowing a malicious authenticated user with network access to execute remote code. This issue is present in versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7, with version 32.1.1 being the most recent vulnerable release.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an authenticated user to execute code remotely on the affected system.

Remediation

Users can upgrade to VMware Avi Load Balancer version 32.1.2, 31.2.2-2p3, or 30.2.7. For version 22.1.x, an upgrade to at least 30.2.7 is required.

Added: Jul 18, 2026, 9:21 AM
Updated: Jul 18, 2026, 9:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.