CVE-2026-47866: Authorization Bypass in VMware Avi Load Balancer
ID: 03ac0aab-0991-52a6-b211-12614a58f5f8
STIX ID: report--03ac0aab-0991-52a6-b211-12614a58f5f8
Feed Name: CosmicBytez Labs
**Executive Summary:** Broadcom disclosed CVE-2026-47866, an authorization bypass in VMware Avi Load Balancer (CVSS 8.3) that allows low-privileged authenticated attackers to access a limited subset of the Control Plane. The advisory lists affected version ranges and patched releases (e.g., 30.2.7, 31.2.2-2p3, 32.1.2), warns that this flaw can be chained with an unauthenticated auth bypass (CVE-2026-47865) and subsequent RCEs, and recommends applying the full patch bundle, auditing low-privilege accounts, monitoring anomalous access, and network segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
