CVE-2026-17192

Arista · VeloCloud Orchestrator On-Prem

A Server-Side Request Forgery vulnerability in the Arista VeloCloud Orchestrator allows authenticated tenant accounts to access restricted internal services.

Executive summary

Arista VeloCloud Orchestrator contains a Server-Side Request Forgery flaw that permits authenticated tenants to access sensitive internal services.

Vulnerability

The vulnerability is a Server-Side Request Forgery (CWE-918) caused by insufficient validation of caller-supplied input. It requires the attacker to have an authenticated tenant account to initiate requests that target internal services otherwise inaccessible from the network.

Business impact

This vulnerability allows a malicious actor with valid tenant credentials to bypass network boundaries and interact with internal administrative or service-level endpoints. With a CVSS score of 8.5, the risk involves potential information disclosure or unauthorized administrative actions within the infrastructure. This could lead to a broader compromise of the orchestration environment and the connected software-defined wide area network.

Remediation

Immediate Action: Upgrade the VeloCloud Orchestrator to versions 5.2.3.14, 6.1.3.4, 6.4.2.4, or later.

Proactive Monitoring: Monitor server logs for unusual outbound requests from the Orchestrator to internal IP addresses or sensitive service ports.

Compensating Controls: Restrict access to the Orchestrator management interface to trusted administrative IP addresses and employ strict egress filtering to prevent unauthorized internal service communication.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the VeloCloud Orchestrator should prioritize the vendor-provided updates. Because this vulnerability facilitates access to internal services, immediate patching is necessary to prevent potential escalation of privileges or unauthorized infrastructure manipulation.