Skip to content
Arista NetworksCVE-2026-17192

Arista Networks VeloCloud Orchestrator On-Prem: server-side request forgery

Medium6.3CVE-2026-17192 · Published Jul 27, 2026 · updated Jul 30, 2026

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

Arista Networks advisory

Affected versions

PackageAffectedFixed in
VeloCloud Orchestrator On-Prem
Product
>= 5.2.0, < 5.2.3.145.2.3.14
>= 6.1.0, < 6.1.3.46.1.3.4
>= 6.4.0, < 6.4.2.46.4.2.4
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-918

More Arista Networks advisories

All Arista Networks
Advisory
Arista Networks EOS: race condition
Low2.1Sep 14
Arista Networks EOS: race condition
Medium5.6Sep 14
Arista Networks EOS: incomplete cleanup
Low2.1Sep 14
Arista Networks EOS: improper access control
Medium5.9Sep 14
Arista Networks VeloCloud Orchestrator On-Prem: SQL injection
High8.5Jul 27
Arista Networks VeloCloud Orchestrator On-Prem: command injection
Critical10.0Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.