CVE-2026-47869: Improper Control of Generation of Code ('Code Injection') in VMware Avi Load Balancer
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
AI Analysis
Technical Summary
VMware Avi Load Balancer contains a remote code execution vulnerability identified as CVE-2026-47869. This vulnerability arises from improper control of code generation, enabling a malicious authenticated user with network access to inject and execute arbitrary code. The affected versions include 22.1.1 through 22.1.7, 30.1.1 through 30.2.6, 31.1.1 through 31.2.2, and 32.1.1. Fixes have been released in versions 30.2.7, 31.2.2-2p3, and 32.1.2 respectively.
Potential Impact
Successful exploitation of this vulnerability could allow an authenticated attacker to execute arbitrary code on the VMware Avi Load Balancer, potentially leading to complete compromise of the affected system. The CVSS score of 8.7 (high severity) reflects the critical impact on confidentiality and integrity, with no impact on availability.
Mitigation Recommendations
Fixes for this vulnerability are available in VMware Avi Load Balancer versions 22.1.8 and later, 30.2.7 and later, 31.2.2-2p3 and later, and 32.1.2 and later. Users should upgrade to these fixed versions to remediate the vulnerability. Patch status is not explicitly confirmed in the vendor advisory, but the presence of fixed versions indicates official fixes are available.
CVE-2026-47869: Improper Control of Generation of Code ('Code Injection') in VMware Avi Load Balancer
Description
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
CVSS v3.1
Score 8.7high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
VMware Avi Load Balancer contains a remote code execution vulnerability identified as CVE-2026-47869. This vulnerability arises from improper control of code generation, enabling a malicious authenticated user with network access to inject and execute arbitrary code. The affected versions include 22.1.1 through 22.1.7, 30.1.1 through 30.2.6, 31.1.1 through 31.2.2, and 32.1.1. Fixes have been released in versions 30.2.7, 31.2.2-2p3, and 32.1.2 respectively.
Potential Impact
Successful exploitation of this vulnerability could allow an authenticated attacker to execute arbitrary code on the VMware Avi Load Balancer, potentially leading to complete compromise of the affected system. The CVSS score of 8.7 (high severity) reflects the critical impact on confidentiality and integrity, with no impact on availability.
Mitigation Recommendations
Fixes for this vulnerability are available in VMware Avi Load Balancer versions 22.1.8 and later, 30.2.7 and later, 31.2.2-2p3 and later, and 32.1.2 and later. Users should upgrade to these fixed versions to remediate the vulnerability. Patch status is not explicitly confirmed in the vendor advisory, but the presence of fixed versions indicates official fixes are available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- vmware
- Date Reserved
- 2026-05-20T10:00:57.077Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5b5ea42d1edb114c7faeb9
Added to database: 07/18/2026, 11:08:20 UTC
Last enriched: 07/25/2026, 22:11:47 UTC
Last updated: 08/30/2026, 22:52:11 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.