CVE-2026-16812
Arista Networks · VeloCloud Orchestrator On-Prem
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
Executive summary
This critical command injection vulnerability in Arista VeloCloud Orchestrator is being actively exploited in the wild and enables full system compromise.
Vulnerability
The vulnerability is an OS command injection (CWE-78) flaw within internal functionality that was not intended for remote access. Unauthenticated attackers can reach this endpoint to execute system commands with high impact on the host.
Business impact
A CVSS score of 10.0 reflects the extreme severity of this flaw, which allows for total compromise of the orchestrator and all managed data. Successful exploitation could lead to full network control, data exfiltration, and significant operational disruption.
Remediation
Immediate Action: Upgrade your on-premise VeloCloud Orchestrator to the fixed release versions specified in the vendor advisory (5.2.3.14, 6.1.3.4, 6.4.2.4, or later in the respective trains).
Proactive Monitoring: Monitor network traffic for unexpected command execution attempts or outbound connections from the orchestrator host to unknown external IPs.
Compensating Controls: Immediately isolate the orchestrator management interface from the public internet using network access control lists or a VPN.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This is an emergency-level security event. Organizations must apply the vendor-provided updates immediately and ensure that all VeloCloud Orchestrator instances are protected from external access until the patch is fully verified and deployed.