CVE-2026-17192
Arista · VeloCloud Orchestrator On-Prem
A Server-Side Request Forgery vulnerability in the Arista VeloCloud Orchestrator allows authenticated tenant accounts to access restricted internal services.
Executive summary
Arista VeloCloud Orchestrator contains a Server-Side Request Forgery flaw that permits authenticated tenants to access sensitive internal services.
Vulnerability
The vulnerability is a Server-Side Request Forgery (CWE-918) caused by insufficient validation of caller-supplied input. It requires the attacker to have an authenticated tenant account to initiate requests that target internal services otherwise inaccessible from the network.
Business impact
This vulnerability allows a malicious actor with valid tenant credentials to bypass network boundaries and interact with internal administrative or service-level endpoints. With a CVSS score of 8.5, the risk involves potential information disclosure or unauthorized administrative actions within the infrastructure. This could lead to a broader compromise of the orchestration environment and the connected software-defined wide area network.
Remediation
Immediate Action: Upgrade the VeloCloud Orchestrator to versions 5.2.3.14, 6.1.3.4, 6.4.2.4, or later.
Proactive Monitoring: Monitor server logs for unusual outbound requests from the Orchestrator to internal IP addresses or sensitive service ports.
Compensating Controls: Restrict access to the Orchestrator management interface to trusted administrative IP addresses and employ strict egress filtering to prevent unauthorized internal service communication.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing the VeloCloud Orchestrator should prioritize the vendor-provided updates. Because this vulnerability facilitates access to internal services, immediate patching is necessary to prevent potential escalation of privileges or unauthorized infrastructure manipulation.