CVE-2026-47871: VMware Avi Load Balancer Directory Traversal
ID: 72993e28-e034-5b5f-9eac-78baea9313e9
STIX ID: report--72993e28-e034-5b5f-9eac-78baea9313e9
Feed Name: CosmicBytez Labs
VMware disclosed CVE-2026-47871, a directory traversal vulnerability in Avi Load Balancer with a CVSS v3.1 base score of 8.8 (High). The flaw allows authenticated network attackers with low privileges and no user interaction to read (and potentially write) sensitive files outside the application directory, impacting confidentiality, integrity, and availability across multiple version branches; VMware published fixed versions and recommended mitigation steps such as isolating the management interface and monitoring for path traversal patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
