CVE-2026-93952

10.0

Arista Networks · VeloCloud Orchestrator (VCO) On-Prem

VeloCloud Orchestrator (VCO) on-prem is vulnerable to improper input validation, allowing unauthenticated remote attackers to access privileged functionality and compromise the host.

Executive summary

A critical vulnerability in Arista Networks VeloCloud Orchestrator (VCO) On-Prem allows unauthenticated remote attackers to gain unauthorized access to privileged functions, posing a severe risk to system integrity.

Vulnerability

The flaw stems from improper input validation (CWE-20) within the VCO on-prem software. This vulnerability allows an unauthenticated remote attacker to bypass security controls and interact with privileged internal functionality, potentially leading to full system compromise.

Business impact

Successful exploitation of this vulnerability grants an attacker unauthorized access to the core orchestrator, which manages network traffic and configuration data. Given the CVSS score of 10.0, the impact includes total loss of confidentiality, integrity, and availability for the VCO host and all associated managed data. Such an event would result in significant operational disruption, potential data exfiltration, and a total loss of trust in the network orchestration layer.

Remediation

Immediate Action: Upgrade your VeloCloud Orchestrator instance to a patched release, specifically versions 5.2.3.16 or 6.4.2.8, or later versions in those respective trains as indicated by the vendor.

Proactive Monitoring: Review system and access logs for unusual administrative activity or unauthorized attempts to access internal API endpoints.

Compensating Controls: Implement strict network segmentation and restrict access to the VCO management interface to trusted IP addresses only, which may limit the attack surface while planning for the necessary upgrade.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for full system compromise, immediate patching is required. Organizations should prioritize the update of all on-prem VCO instances to the remediated versions specified by Arista Networks. If immediate patching is not feasible, restrict network access to the management interface to the absolute minimum necessary to maintain operations.

More Arista Networks CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources