CVE-2026-93952
10.0Arista Networks · VeloCloud Orchestrator (VCO) On-Prem
VeloCloud Orchestrator (VCO) on-prem is vulnerable to improper input validation, allowing unauthenticated remote attackers to access privileged functionality and compromise the host.
Executive summary
A critical vulnerability in Arista Networks VeloCloud Orchestrator (VCO) On-Prem allows unauthenticated remote attackers to gain unauthorized access to privileged functions, posing a severe risk to system integrity.
Vulnerability
The flaw stems from improper input validation (CWE-20) within the VCO on-prem software. This vulnerability allows an unauthenticated remote attacker to bypass security controls and interact with privileged internal functionality, potentially leading to full system compromise.
Business impact
Successful exploitation of this vulnerability grants an attacker unauthorized access to the core orchestrator, which manages network traffic and configuration data. Given the CVSS score of 10.0, the impact includes total loss of confidentiality, integrity, and availability for the VCO host and all associated managed data. Such an event would result in significant operational disruption, potential data exfiltration, and a total loss of trust in the network orchestration layer.
Remediation
Immediate Action: Upgrade your VeloCloud Orchestrator instance to a patched release, specifically versions 5.2.3.16 or 6.4.2.8, or later versions in those respective trains as indicated by the vendor.
Proactive Monitoring: Review system and access logs for unusual administrative activity or unauthorized attempts to access internal API endpoints.
Compensating Controls: Implement strict network segmentation and restrict access to the VCO management interface to trusted IP addresses only, which may limit the attack surface while planning for the necessary upgrade.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for full system compromise, immediate patching is required. Organizations should prioritize the update of all on-prem VCO instances to the remediated versions specified by Arista Networks. If immediate patching is not feasible, restrict network access to the management interface to the absolute minimum necessary to maintain operations.
More Arista Networks CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
- Security Advisory 0183 Vendor advisory