Arista NetworksCVE-2026-17192
Arista Networks VeloCloud Orchestrator On-Prem: server-side request forgery
Medium6.3CVE-2026-17192 · Published Jul 27, 2026 · updated Jul 30, 2026
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| VeloCloud Orchestrator On-Prem Product | >= 5.2.0, < 5.2.3.14 | 5.2.3.14 |
| >= 6.1.0, < 6.1.3.4 | 6.1.3.4 | |
| >= 6.4.0, < 6.4.2.4 | 6.4.2.4 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
More Arista Networks advisories
All Arista Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 14 | Arista Networks EOS: race condition | Low2.1 | No fix yet |
| Sep 14 | Arista Networks EOS: race condition | Medium5.6 | No fix yet |
| Sep 14 | Arista Networks EOS: incomplete cleanup | Low2.1 | No fix yet |
| Sep 14 | Arista Networks EOS: improper access control | Medium5.9 | No fix yet |
| Jul 27 | Arista Networks VeloCloud Orchestrator On-Prem: SQL injection | High8.5 | 5.2.3.14+2 more |
| Jul 27 | Arista Networks VeloCloud Orchestrator On-Prem: command injection | Critical10.0 | 5.2.3.14+3 more |