Summary
CVE-2026-47865 is a critical authentication bypass vulnerability (CWE-287: Improper Authentication) in VMware Avi Load Balancer, assigned a CVSS v3.1 base score of 9.8. A malicious actor with network access can bypass the Avi Controller’s authentication mechanism and gain unauthorized access to the Avi Control Plane without any credentials or user interaction. Broadcom has confirmed that no workarounds exist — patching is the only remediation.
Technical details
- Root cause: Improper Authentication (CWE-287) in the Avi Controller component allows the authentication mechanism to be bypassed entirely.
- Trigger conditions: An attacker requires only network-level access to an exposed Avi Controller interface; no credentials, prior foothold, or user interaction are required.
- Attack vector: Remote, unauthenticated exploitation over the network (AV:N/AC:L/PR:N/UI:N).
- Impact: Unauthorized access to the Avi Control Plane — the centralized management layer governing Service Engines, virtual services, SSL/TLS certificates, backend server pools, and traffic routing policy across the entire load balancer infrastructure.
Affected software
- VMware Avi Load Balancer 22.1.1 through 22.1.7
- VMware Avi Load Balancer 30.1.1 through 30.2.6
- VMware Avi Load Balancer 31.1.1 through 31.2.2
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate — upgrade to a fixed version:
- 31.2.2-2p3 for installations on the 31.x branch
- 30.2.7 for installations on the 30.x and 22.x branches
- Broadcom has confirmed no workarounds are available; upgrading is the only remediation.
- As a defense-in-depth measure while patching is arranged, restrict network access to Avi Controller management interfaces to trusted administrative IP ranges only.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

