Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-93952: Arista VeloCloud Orchestrator allows remote access to internal functions

CVE-2026-93952 · published 5 days ago · actively exploited
Summary

The on‑premise VeloCloud Orchestrator can be tricked into accepting crafted input, letting a remote attacker reach privileged features. This could let the attacker view, alter, or disrupt the system and the data it manages. Install the latest vendor update and limit network access to the Orchestrator while monitoring for unusual activity.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
arista networks velocloud orchestrator (vco) on-prem <= 5.2.3.15
arista velocloud orchestrator All versions
arista velocloud_orchestrator >= 5.2.0, < 5.2.3.16
>= 6.1.0, <= 6.1.3.7
>= 6.4.0, < 6.4.2.8
>= 7.0.0, <= 7.0.0.2
cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*
Original advisory text
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Severity
9.5 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published22 Sep 2026
Updated27 Sep 2026
First seen22 Sep 2026
Sources
CVE-2026-93952 · MITRE
CVE-2026-93952 · CISA KEV
Track software like this
Free during beta