CVE-2020-26552: Aviatrix Controller

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints, do not require a valid session ID for access.

Affected products

  • Aviatrix Controller: version 5.3.1516 only

Published 2020-11-17. Last modified 2026-06-17.