Description
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.




This functionality was intended to be for internal use only and is not intended to be remotely accessible.




Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.




This issue was discovered externally and is known to be actively exploited.
Published: 2026-07-27
Score: 10 Critical
EPSS: < 1% Very Low
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an OS command injection flaw in the VeloCloud Orchestrator (VCO) on‑prem web interface that can be triggered remotely. An attacker who successfully abuses the flaw can execute arbitrary commands with the privileges of the VCO service, gaining full control over the orchestrator host. The result is a compromise of confidentiality, integrity, and availability of the orchestrator and the network data it manages.

Affected Systems

Arista Networks VeloCloud Orchestrator On‑Prem is affected. All VCO releases prior to the listed fixed builds are vulnerable: VCO 5.2 train versions earlier than 5.2.3.14, VCO 6.1 train versions earlier than 6.1.3.4, and VCO 6.4 train versions earlier than 6.4.2.4. Systems on unsupported trains should contact TAC for upgrade guidance.

Risk and Exploitability

The vulnerability scores a CVSS of 10, indicating maximum severity. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. It is known to be actively exploited and is listed in CISA’s KEV catalog. The VCO web interface is intended for internal use and therefore is expected to be trusted, but the flaw exposes it to remote attackers. Exploitation requires sending malicious input to the vulnerable endpoint, resulting in remote execution of arbitrary commands on the host.

Generated by OpenCVE AI on August 3, 2026 at 17:11 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a fixed VCO release at your earliest convenience. This vulnerability has been fixed in the following releases:   * VCO 5.2.3.14 and later in the 5.2 train * VCO 6.1.3.4 and later in the 6.1 train * VCO 6.4.2.4 and later in the 6.4 train


Vendor Workaround

The recommended resolution is to upgrade to a fixed VCO release as soon as it is available. For VCOs which are not on a supported release train, customers can contact TAC to discuss possible upgrade options for your release. Until the fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment: * Restrict access to the VCO web interface to trusted administrative networks. * Monitor the VCO for accesses from known malicious source IPs. * Monitor for unexpected outbound network activity from the VCO host. * Review recent administrator activity for unexpected changes.


OpenCVE Recommended Actions

  • Upgrade VCO to a fixed release: 5.2.3.14 or later in the 5.2 train, 6.1.3.4 or later in the 6.1 train, or 6.4.2.4 or later in the 6.4 train.
  • Restrict access to the VCO web interface so it is only reachable from trusted administrative networks.
  • Monitor the VCO for connections from known malicious source IPs and for unexpected outbound traffic from the host.
  • Review recent administrator activity for unexpected changes to ensure no compromise has occurred.

Generated by OpenCVE AI on August 3, 2026 at 17:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Arista Networks
Arista Networks velocloud Orchestrator On-prem
Vendors & Products Arista Networks
Arista Networks velocloud Orchestrator On-prem

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

kev

{'dateAdded': '2026-07-27T00:00:00+00:00', 'dueDate': '2026-07-30T00:00:00+00:00'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.
Title VeloCloud Orchestrator OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P'}


Subscriptions

Arista Velocloud Orchestrator
Arista Networks Velocloud Orchestrator On-prem
cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-07-28T03:56:40.567Z

Reserved: 2026-07-23T21:46:32.558Z

Link: CVE-2026-16812

cve-icon Vulnrichment

Updated: 2026-07-27T16:53:57.520Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T16:17:03.640

Modified: 2026-07-28T14:50:33.960

Link: CVE-2026-16812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:15:12Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')