Description
Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Command execution with elevated privileges
Action: Apply Patch
AI Analysis

Impact

Insufficient validation of inputs supplied through the management and configuration workflows of Arista VeloCloud Edge allows an authorized manager to provide values that are interpreted as operating‑system commands. The vulnerability aligns with OS command injection (CWE‑78) and permits command execution at the device’s operating‑system level, potentially compromising the entire Edge device.

Affected Systems

The affected product is Arista Networks’ VeloCloud Edge. The specific software versions are not enumerated in the advisory, but the issue applies to all current releases within a supported branch until a patched version is deployed.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, while the EPSS score of <1% suggests a low probability of exploitation today. The vulnerability requires an account with authorized management or configuration privileges, so an adversary must first gain or possess legitimate credentials. The direct impact is remote code execution on the device. The advisory is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 16, 2026 at 17:08 UTC.

Remediation

Vendor Solution

Migrating to a patched software version for VeloCloud Edge is the advised course of action. Arista suggests that operators transition to the most recent release within a supported branch that incorporates the necessary remediations.


Vendor Workaround

1. Restrict VeloCloud Orchestrator Super Admin and Operator roles, particularly Remote Diagnostics and device-configuration access, to trusted personnel. 2. Protect Orchestrator administrative credentials and management access. 3. Maintain the default Local UI access restrictions and limit activation access to authorized personnel.


OpenCVE Recommended Actions

  • Upgrade VeloCloud Edge to a patched release that implements the input validation fix.
  • Restrict Orchestrator Super Admin and Operator roles, limiting Remote Diagnostics and device-configuration access to trusted personnel.
  • Secure Orchestrator administrative credentials and enforce strict management access controls.

Generated by OpenCVE AI on September 16, 2026 at 17:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
Title Security Advisory 0181
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-17T17:41:11.191Z

Reserved: 2026-09-05T01:54:43.258Z

Link: CVE-2026-86108

cve-icon Vulnrichment

Updated: 2026-09-17T17:41:06.643Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T03:17:00.077

Modified: 2026-09-17T18:17:12.320

Link: CVE-2026-86108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T17:15:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')