CVE-2024-22264: VMware Avi Load Balancer

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMware Avi Load Balancer can create, modify, execute and delete files as a root user on the host system.

Affected products

  • VMware VMware Avi Load Balancer: from 22.1, before 22.1.6 (fixed in 22.1.6); from 30.x.x, before 30.2.1 (fixed in 30.2.1); version 22.10.0 only; version 30.0.0 only

Published 2024-05-08. Last modified 2026-06-17.