Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-86106: Arista Velocloud Edge HA can allow remote command execution

CVE-2026-86106 · published 11 days ago
Summary

Anyone on the same network as the private HA link between Edge devices can trigger privileged actions without proving their identity. This can give them the ability to run commands with higher privileges on Edge units that have HA turned on. Limit access to the HA interconnect, apply the latest firmware, and separate HA traffic from other networks.

What to do
  • Update arista networks velocloud edge to version 5.2.0.0 or later.
Affected software
VendorProductAffected versions
arista networks velocloud edge < 5.2.0.0
Original advisory text
Security Advisory 0179
An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.
Severity
8.7 High
CVSS 3.1: 9.6 (MITRE)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published16 Sep 2026
Updated27 Sep 2026
First seen16 Sep 2026
Sources
CVE-2026-86106 · MITRE
Track software like this
Free during beta