CVE-2026-47865: Critical Authentication Bypass in VMware Avi Load Balancer
ID: d5699b0b-832d-5efa-afe8-b488570b1cfe
STIX ID: report--d5699b0b-832d-5efa-afe8-b488570b1cfe
Feed Name: CosmicBytez Labs
**CVE-2026-47865 — Authentication bypass in Broadcom/VMware Avi Load Balancer (CVSS 9.8).** An unauthenticated attacker with network access can completely bypass Control Plane authentication and obtain full confidentiality, integrity, and availability impact; affected versions include 22.1.1–22.1.7, 30.1.1–30.2.6, and 31.1.1–31.2.2, with patches available in 30.2.7 and 31.2.2-2p3. Broadcom recommends immediate patching (no workaround), restricting access until patched, and auditing logs for anomalous access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
