Skip to content
Arista NetworksCVE-2026-17191

Arista Networks VeloCloud Orchestrator On-Prem: SQL injection

High8.5CVE-2026-17191 · Published Jul 27, 2026 · updated Jul 30, 2026

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

Arista Networks advisory

Affected versions

PackageAffectedFixed in
VeloCloud Orchestrator On-Prem
Product
>= 5.2.0, < 5.2.3.145.2.3.14
>= 6.1.0, < 6.1.3.46.1.3.4
>= 6.4.0, < 6.4.2.46.4.2.4
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-89

More Arista Networks advisories

All Arista Networks
Advisory
Arista Networks EOS: race condition
Low2.1Sep 14
Arista Networks EOS: race condition
Medium5.6Sep 14
Arista Networks EOS: incomplete cleanup
Low2.1Sep 14
Arista Networks EOS: improper access control
Medium5.9Sep 14
Arista Networks VeloCloud Orchestrator On-Prem: server-side request forgery
Medium6.3Jul 27
Arista Networks VeloCloud Orchestrator On-Prem: command injection
Critical10.0Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.