VMware Avi Load Balancer Directory Traversal Vulnerability

Vulnerability

A directory traversal vulnerability has been identified in VMware Avi Load Balancer. This issue arises from inadequate file path validation, allowing malicious authenticated network users to perform directory traversal attacks. The vulnerability is present in versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7, with version 32.1.1 being the most recent vulnerable release.

Impact

Exploitation of this vulnerability could lead to unauthorized access to restricted directories, potentially allowing for the manipulation or exposure of files outside the intended directory structure.

Remediation

Users can upgrade to VMware Avi Load Balancer version 32.1.2, 31.2.2-2p3, or 30.2.7 to address this vulnerability. Version 22.1.x must be upgraded to at least 30.2.7 or later.

Added: Jul 18, 2026, 9:21 AM
Updated: Jul 18, 2026, 9:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.