Arista NetworksCVE-2026-86106
Arista Networks VeloCloud Edge: missing authentication
High8.7CVE-2026-86106 · Published Sep 16, 2026
An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| VeloCloud Edge Product | >= 1.0.0.0, < 5.2.0.0 | 5.2.0.0 |
| >= 5.2.0.0, < 5.2.7.0 | 5.2.7.0 | |
| >= 6.1.0.0, < 6.1.5.0 | 6.1.5.0 | |
| >= 6.4.0.0, < 6.4.2.0 | 6.4.2.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-306
More Arista Networks advisories
All Arista Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | Arista Networks EOS: remote code execution | Critical9.2 | No fix yet |
| Sep 16 | Arista Networks EOS: secrets in logs | Medium6.0 | No fix yet |
| Sep 16 | Arista Networks EOS: out-of-bounds read | High7.1 | No fix yet |
| Sep 16 | Arista Networks EOS: secrets in logs | Low2.1 | No fix yet |
| Sep 16 | Arista Networks EOS: denial of service | Medium5.3 | No fix yet |
| Sep 16 | Arista Networks VeloCloud: out-of-bounds write | High8.2 | 5.2.0.0+3 more |