Description
The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The VeloCloud Edge update workflow allows installation of software bundles without properly validating their signatures because the digest algorithm used for artifact verification is not restricted, a weakness that falls under CWE-347. As a result, an attacker who can upload packages to VeloCloud Orchestrator or who has credentials that provide direct access to an Edge device can install unauthorized software. The CVE description does not explicitly state the outcome, but the ability to install arbitrary software suggests the potential for remote code execution, an effect that is inferred from the vulnerability’s nature.

Affected Systems

Arista Networks VeloCloud Edge software. No specific version information is provided in the advisory, so all releases of VeloCloud Edge in supported branches that have not yet applied the fix are potentially affected.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high severity vulnerability. The EPSS score is less than 1%, implying a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The path to exploitation requires either privileged upload rights to the Orchestrator or direct administrative credentials to an Edge device, after which the attacker can push and install a malicious bundle through the update workflow.

Generated by OpenCVE AI on September 16, 2026 at 17:36 UTC.

Remediation

Vendor Solution

Migrating to a patched software version for VeloCloud Edge is the advised course of action. Arista suggests that operators transition to the most recent release within a supported branch that incorporates the necessary remediations.


Vendor Workaround

1. Restrict software-image management and VeloCloud Edge update privileges to trusted administrators. 2. Protect VeloCloud Orchestrator administrative credentials and management access. 3. Obtain and distribute VeloCloud Edge software only through trusted Arista management and distribution channels. 4. Investigate unexpected software images or update operations before permitting installation. These measures reduce exposure but do not correct the vulnerable update-verification workflow.


OpenCVE Recommended Actions

  • Upgrade to the latest patched version of VeloCloud Edge that incorporates the missing signature verification fix.
  • Restrict software-image management and VeloCloud Edge update privileges to trusted administrators.
  • Protect VeloCloud Orchestrator administrative credentials and limit management access.
  • Obtain and distribute VeloCloud Edge software only through trusted Arista management and distribution channels.
  • Investigate unexpected software image or update operations before permitting installation.

Generated by OpenCVE AI on September 16, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.
Title Security Advisory 0182
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-17T17:40:35.095Z

Reserved: 2026-09-05T01:54:43.258Z

Link: CVE-2026-86109

cve-icon Vulnrichment

Updated: 2026-09-17T17:40:29.499Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T03:17:00.250

Modified: 2026-09-17T18:17:12.480

Link: CVE-2026-86109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T17:45:17Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature