Description
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
Published: 2026-09-22
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

VeloCloud Orchestrator on‑prem exposes privileged internal functionality that can be accessed by a remote attacker, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages. The vulnerability enables exploitation that may allow the attacker to gain high‑privilege access and control of the host system.

Affected Systems

Arista Networks VeloCloud Orchestrator (VCO) On‑Prem is affected. All flavors, including Hosted and Dedicated, were impacted. The vulnerability has already been patched by Arista; the correct fix requires upgrading to VCO 5.2.3.16 or later in the 5.2.3 train, or VCO 6.4.2.8 or later in the 6.4.2 train. Systems on unsupported release trains should contact TAC for upgrade options.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.5, reflecting a high severity and the potential for full remote compromise. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. Although the exact attack vector is not explicitly detailed, it is inferred that the web interface is likely the entry point, meaning an attacker may exploit the flaw over the network. The combination of high severity and network reach indicates a significant risk if left unpatched.

Generated by OpenCVE AI on September 22, 2026 at 08:21 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated VCO software version at your earliest convenience. These vulnerabilities have been fixed in the following releases: - VCO 5.2.3.16 and later in the 5.2.3 train - VCO 6.4.2.8 and later in the 6.4.2 train Releases in other release trains that fix this will be added over time. For VCOs not on a supported release train, customers can contact TAC to discuss possible upgrade options.


Vendor Workaround

Until fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment: - Restrict access to the VCO web interface to trusted administrative networks. - Monitor the VCO for accesses from known malicious source IPs. - Monitor for unexpected outbound network activity from the VCO host. - Consider blocking outbound ports not needed for normal activities. - Monitor for backdoor daemons and webshells. - Review recent administrator activity for unexpected changes.


OpenCVE Recommended Actions

  • Upgrade the VCO to version 5.2.3.16 or later in the 5.2.3 train or to 6.4.2.8 or later in the 6.4.2 train.
  • If the orchestrator is on an unsupported release train, contact TAC to discuss upgrade options.
  • Restrict access to the VCO web interface to trusted administrative networks.
  • Monitor the VCO for connections from known malicious IP addresses and for unexpected outbound traffic.
  • Block outbound ports that are not required for normal VCO operations.
  • Keep watch for backdoor daemons or webshells and review recent administrator activity for unexpected changes.

Generated by OpenCVE AI on September 22, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
Title Security Advisory 0183
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-22T13:14:07.101Z

Reserved: 2026-09-19T01:37:47.225Z

Link: CVE-2026-93952

cve-icon Vulnrichment

Updated: 2026-09-22T13:14:01.833Z

cve-icon NVD

Status : Received

Published: 2026-09-22T08:16:43.047

Modified: 2026-09-22T14:17:18.643

Link: CVE-2026-93952

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T08:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation