---
schema: 1
kind: vulnerability
title: "CVE-2026-47865 — VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround"
headline: "Broadcom patches a pre-auth authentication bypass on the VMware Avi Load Balancer control plane (CVE-2026-47865), reported by NATO NCSC"
summary: >
  Broadcom advisory VMSA-2026-0005 (2026-07-14) discloses seven flaws in VMware Avi Load Balancer
  (formerly NSX Advanced Load Balancer); the headline flaw CVE-2026-47865 (CVSS 9.8) lets an
  unauthenticated remote attacker reach the Avi Controller control plane by bypassing
  authentication entirely, with no workaround available. Affected: 22.1.1–22.1.7, 30.1.1–30.2.6,
  31.1.1–31.2.2 and 32.1.1; fixed in 32.1.2, 31.2.2-2p3 and 30.2.7. No in-the-wild exploitation is
  reported, but the bug was reported by NATO NCSC and the control plane governs traffic routing and
  TLS termination for whatever sits behind the load balancer.
discovered_at: "2026-07-18T04:35:00Z"
event_date: "2026-07-14"
run_id: 2026-07-18T0409Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, auth-bypass, pre-auth, no-patch, cloud]
regions: [global, europe]
sectors: [public-sector, finance, healthcare, telco, energy]
entities: []
techniques: [T1190, T1068]
affected_products: ["VMware Avi Load Balancer", "VMware NSX Advanced Load Balancer"]
cves:
  - id: CVE-2026-47865
    cvss: "9.8"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2"
    fixed: "32.1.2 / 31.2.2-2p3 / 30.2.7"
  - id: CVE-2026-47867
    cvss: "8.7"
    epss: null
    type: rce
    vector: zero-click
    auth: admin-required
    status: [patch-available]
    affected: "22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2, 32.1.1"
    fixed: "32.1.2 / 31.2.2-2p3 / 30.2.7"
  - id: CVE-2026-47871
    cvss: "8.8"
    epss: null
    type: path-traversal
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2, 32.1.1"
    fixed: "32.1.2 / 31.2.2-2p3 / 30.2.7"
  - id: CVE-2026-47868
    cvss: "7.8"
    epss: null
    type: lpe
    vector: local
    auth: post-auth
    status: [patch-available]
    affected: "22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2, 32.1.1"
    fixed: "32.1.2 / 31.2.2-2p3 / 30.2.7"
  - id: CVE-2026-47866
    cvss: "8.3"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2, 32.1.1"
    fixed: "32.1.2 / 31.2.2-2p3 / 30.2.7"
  - id: CVE-2026-47869
    cvss: "8.7"
    epss: null
    type: rce
    vector: zero-click
    auth: admin-required
    status: [patch-available]
    affected: "22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2, 32.1.1"
    fixed: "32.1.2 / 31.2.2-2p3 / 30.2.7"
  - id: CVE-2026-47870
    cvss: "7.1"
    epss: null
    type: priv-esc
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2, 32.1.1"
    fixed: "32.1.2 / 31.2.2-2p3 / 30.2.7"
sources:
  - url: "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926"
    publisher: "Broadcom / VMware PSIRT (VMSA-2026-0005)"
    date: "2026-07-14"
    role: primary
  - url: "https://www.heise.de/news/VMware-Avi-Load-Balancer-Kritische-Luecke-erlaubt-Umgehung-von-Anmeldung-11368661.html"
    publisher: "heise Security"
    date: "2026-07-17"
    role: corroborating
closed_sources: []
evidence:
  - quote: "A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism."
    publisher: "Broadcom / VMware PSIRT (VMSA-2026-0005)"
verification: multi-source
sourcing_note: "Vendor PSIRT for its own product (Broadcom, Admiralty A) corroborated by heise Security's re-reporting; CVE-2026-47865 credited to Filip Waeytens of the NATO NCSC. No independent confirmation of exploitation — none is claimed."
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions: []
migrated_from: null
---

Broadcom's VMSA-2026-0005 (2026-07-14, last updated 2026-07-15) patches seven vulnerabilities in VMware Avi Load Balancer — the load-balancing/application-delivery product formerly sold as NSX Advanced Load Balancer and widely deployed in enterprise and government data-centre fabric across Europe. The load-bearing flaw, **CVE-2026-47865** (CVSS 9.8), is an authentication bypass on the Avi Controller: "a malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism" — no credentials, no user interaction ([Broadcom PSIRT, 2026-07-14](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926)). The advisory ships six companion flaws that require a prior foothold: two high-privilege remote code-execution bugs (CVE-2026-47867, CVE-2026-47869, both CVSS 8.7, PR:H), a low-privilege authenticated directory traversal (CVE-2026-47871, CVSS 8.8), an authorization bypass (CVE-2026-47866, CVSS 8.3), a local-to-root privilege escalation (CVE-2026-47868, CVSS 7.8) and a further privilege escalation (CVE-2026-47870, CVSS 7.1). Broadcom states no workarounds exist ([Broadcom PSIRT, 2026-07-14](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926)); the German trade press summarised it as attackers being able to bypass authentication and authorization ([heise Security, 2026-07-17](https://www.heise.de/news/VMware-Avi-Load-Balancer-Kritische-Luecke-erlaubt-Umgehung-von-Anmeldung-11368661.html)).

No in-the-wild exploitation has been reported, but two facts raise this above the routine patch cycle: the reporter is the NATO NCSC (a direct constituency-provenance signal), and there is no mitigation short of upgrading. Because the Avi Controller is the management and orchestration plane for the load-balancing fabric, an unauthenticated bypass there is a direct path to reconfiguring traffic routing and TLS termination for every service behind the load balancer — an interception and traffic-manipulation position, not merely appliance compromise.

**Defender takeaway:** Upgrade the Avi Controller to a fixed release — 32.1.2 (recommended), 31.2.2-2p3 or 30.2.7; the 22.1.x branch must move to at least 30.2.7. Because no workaround exists, until the upgrade lands restrict Controller management-plane reachability to trusted management VLANs/jump hosts and treat any exposure of the Avi Controller to broad or untrusted network segments as the finding in its own right. Detection concept, telemetry-class first: Avi Controller admin/API authentication logs showing control-plane session establishment or API calls with no preceding successful login event, particularly from source ranges outside the management network.
