ON
← Back to feed
VMware Avi Load Balancer: Critical loophole allows bypass of the login
Germany🏛️ Politics20 days ago

VMware Avi Load Balancer: Critical loophole allows bypass of the login

VMware’s Avi Load Balancer wurde von Broadcom als Sicherheitsanbieter über mehrere kritische und hochkritische Schwachstellen informiert. Die schwerwiegendste Lücke (CVE-2026-47865, CVSS 9.8) ermöglicht Angreifern mit Netzwerkzugriff, den Authentifizierungsmechanismus zu umgehen. Weitere Schwachstellen umfassen eine Directory-Traversal-Lücke, eine Codeschmuggel-Lücke sowie Möglichkeiten zur unbefugten Änderung von Einstellungen oder Ausführung von Schadcode als Root-User. Broadcom bietet Updates für Versionen 32.1.2, 31.2.2-2p3 und 30.2.7 an, wobei Nutzer, die ältere Versionen (22.1.1–22.1.7) nutzen, dringend auf diese Versionen migrieren sollten. Zuvor hatten die Entwickler bereits andere Schwachstellen in VMware-Produkten gemeldet, allerdings mit geringerer Risikobewertung.

VMware has issued security updates for its Avi Load Balancer after multiple critical vulnerabilities were discovered that could allow attackers to bypass authentication mechanisms. The flaws, which affect several versions of the product, have been classified with high and critical risk ratings, according to a security advisory released by Broadcom, the company behind Avi. The most severe vulnerability, designated CVE-2026-47865, allows malicious actors with network access to bypass the authentication process on the Avi Controller interface. This means unauthorized users could gain entry to sensitive systems without needing valid credentials. While Broadcom did not provide detailed information on how exactly the flaw can be exploited or where it was located within the system architecture, the severity rating indicates a serious threat. Other notable issues include a directory traversal vulnerability (CVE-2026-47871), a code smuggling flaw in the Avi Controller (CVE-2026-47867), and a vulnerability that enables authenticated users to inject and execute malicious code (CVE-2026-47869). These flaws collectively pose a substantial risk to the integrity and confidentiality of data managed by the load balancer. Additionally, attackers could potentially access certain settings on the Avi Controller without authorization (CVE-2026-47866). Users with local access might also expand their privileges and run code as a root user (CVE-2026-47868). Even malicious users who are already logged into the system from the network could exploit this flaw (CVE-2026-47870). These vulnerabilities highlight the need for immediate patching to prevent potential breaches. Broadcom’s developers have released updated software versions to address these issues. Affected customers using versions of the Avi Load Balancer prior to 32.1.2, 31.2.2-2p3, or 30.2.7 are advised to upgrade to one of these patched versions. Specifically, users running versions 22.1.1 through 22.1.7 should migrate to version 30.2.7 to ensure they are protected against known exploits. This update follows a previous round of security advisories from Broadcom in early June, which identified cross-site scripting vulnerabilities in products such as VMware Cloud Foundation. Those issues were rated as high-risk but did not reach the level of criticality seen in the current set of flaws. In response, Broadcom distributed updated software to mitigate those risks. The discovery of these vulnerabilities underscores the importance of regular software maintenance and timely patch application, especially for enterprise-grade infrastructure components like load balancers. Organizations relying on Avi Load Balancer must assess their current deployment status and apply the necessary patches to safeguard their networks from potential exploitation. As the cybersecurity landscape continues to evolve, proactive measures remain essential in defending against emerging threats.

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 8020 days ago
VMware Avi Load Balancer: Critical loophole allows bypass of the login

VMware’s Avi Load Balancer wurde von Broadcom als Sicherheitsanbieter über mehrere kritische und hochkritische Schwachstellen informiert. Die schwerwiegendste Lücke (CVE-2026-47865, CVSS 9.8) ermöglicht Angreifern mit Netzwerkzugriff, den Authentifizierungsmechanismus zu umgehen. Weitere Schwachstellen umfassen eine Directory-Traversal-Lücke, eine Codeschmuggel-Lücke sowie Möglichkeiten zur unbefugten Änderung von Einstellungen oder Ausführung von Schadcode als Root-User. Broadcom bietet Updates für Versionen 32.1.2, 31.2.2-2p3 und 30.2.7 an, wobei Nutzer, die ältere Versionen (22.1.1–22.1.7) nutzen, dringend auf diese Versionen migrieren sollten. Zuvor hatten die Entwickler bereits andere Schwachstellen in VMware-Produkten gemeldet, allerdings mit geringerer Risikobewertung.

Bias read (Center): Die Berichterstattung konzentriert sich rein auf technische Aspekte der Sicherheitslücken und deren Behandlung durch Broadcom. Es wird keine politische Einordnung oder Bewertung der Schwachstellen vorgenommen. Der Artikel bleibt sachlich und berichtet neutral über die Sicherheitsupdates und Risiken,

Why factuality (85): The article accurately reports the critical security vulnerabilities in VMware Avi Load Balancer as outlined in the primary source document from Broadcom. It lists the relevant CVE identifiers, severity ratings, and mentions the recommended patches. However, it omits some specific details such as th

Why objectivity (80): The tone remains neutral and informative, focusing on the technical aspects of the vulnerabilities. The article does not take sides or express strong opinions, though it uses slightly more dramatic language ('kritische Lücke', 'bösartigen Akteuren') compared to the official advisory.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories