Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-16812: VeloCloud Orchestrator: Unauthorized Access to Internal Functions

CVE-2026-16812 · published 2 months ago · actively exploited
Summary

The VeloCloud Orchestrator, a software used for network management, has a security flaw that could allow an attacker to access internal features remotely. This could lead to unauthorized access to sensitive data and disrupt the normal operation of the system. If you're using the VeloCloud Orchestrator, you should check with your provider to see if they've already applied the necessary patches.

What to do
  • Update arista networks velocloud orchestrator on-prem to version 5.2.3.14 or later.
Affected software
VendorProductAffected versions
arista velocloud orchestrator All versions
arista networks velocloud orchestrator on-prem < 5.2.3.14
Original advisory text
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 10.0 (NVD)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS 1%
Type
CWE-78OS Command Injection
Timeline
Published27 Jul 2026
Updated27 Sep 2026
First seen27 Jul 2026
Sources
CVE-2026-16812 · MITRE
CVE-2026-16812 · CISA KEV
Track software like this
Free during beta