CVE-2026-17192

8.5

Arista · VeloCloud Orchestrator On-Prem

A Server-Side Request Forgery vulnerability in the Arista VeloCloud Orchestrator allows authenticated tenant accounts to access restricted internal services.

Executive summary

Arista VeloCloud Orchestrator contains a Server-Side Request Forgery flaw that permits authenticated tenants to access sensitive internal services.

Vulnerability

The vulnerability is a Server-Side Request Forgery (CWE-918) caused by insufficient validation of caller-supplied input. It requires the attacker to have an authenticated tenant account to initiate requests that target internal services otherwise inaccessible from the network.

Business impact

This vulnerability allows a malicious actor with valid tenant credentials to bypass network boundaries and interact with internal administrative or service-level endpoints. With a CVSS score of 8.5, the risk involves potential information disclosure or unauthorized administrative actions within the infrastructure. This could lead to a broader compromise of the orchestration environment and the connected software-defined wide area network.

Remediation

Immediate Action: Upgrade the VeloCloud Orchestrator to versions 5.2.3.14, 6.1.3.4, 6.4.2.4, or later.

Proactive Monitoring: Monitor server logs for unusual outbound requests from the Orchestrator to internal IP addresses or sensitive service ports.

Compensating Controls: Restrict access to the Orchestrator management interface to trusted administrative IP addresses and employ strict egress filtering to prevent unauthorized internal service communication.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the VeloCloud Orchestrator should prioritize the vendor-provided updates. Because this vulnerability facilitates access to internal services, immediate patching is necessary to prevent potential escalation of privileges or unauthorized infrastructure manipulation.

More Arista CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Fix documented version 5.2.3.14 per CVE record