Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-17191: VeloCloud Orchestrator SQL Injection Risk: Unauthorized Data Access

CVE-2026-17191 · published 2 months ago
Summary

The VeloCloud Orchestrator's API component has a security flaw that could allow an authenticated user to access sensitive data they shouldn't have access to. This issue was found internally by Arista, and there's no evidence it's been exploited by malicious users. Arista is likely working to fix this issue.

What to do
  • Update arista networks velocloud orchestrator on-prem to version 5.2.3.14 or later.
Affected software
VendorProductAffected versions
arista networks velocloud orchestrator on-prem < 5.2.3.14
Original advisory text
VeloCloud Orchestrator Flow Metrics API SQL Injection
An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections.




This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Severity
9.1 Critical
CVSS 3.1: 9.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published27 Jul 2026
Updated27 Sep 2026
First seen27 Jul 2026
Sources
CVE-2026-17191 · MITRE
Track software like this
Free during beta