← All Advisories

VMware Avi Load Balancer Local Privilege Escalation Flaw Allows a Locally Authenticated User to Gain Root Access

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-47868

Key Details

CVECVE-2026-47868
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-08-20
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsBroadcom vmware_avi_load_balancer
Classified asCWE-269 (Improper Privilege Management)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Broadcomvmware_avi_load_balancer
SubsystemsGeneral OT
SectorsMultiple

What to Know

VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root.

Affected versions:

32.1.1 (fixed in 32.1.2)

31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)

30.1.1 through 30.2.6 (fixed in 30.2.7)

22.1.1 through 22.1.7 (fixed in 30.2.7) (NVD)

What to Do

Monitor Broadcom's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-47868
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-47868
Vendor advisoryhttps://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926