logo

CVE-2026-47871: VMware Avi Load Balancer Directory Traversal

ID: 72993e28-e034-5b5f-9eac-78baea9313e9

STIX ID: report--72993e28-e034-5b5f-9eac-78baea9313e9

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-07-19

Date Updated: 2026-07-19

...
...

VMware disclosed CVE-2026-47871, a directory traversal vulnerability in Avi Load Balancer with a CVSS v3.1 base score of 8.8 (High). The flaw allows authenticated network attackers with low privileges and no user interaction to read (and potentially write) sensitive files outside the application directory, impacting confidentiality, integrity, and availability across multiple version branches; VMware published fixed versions and recommended mitigation steps such as isolating the management interface and monitoring for path traversal patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.