Arista NetworksCVE-2026-86108
Arista Networks VeloCloud Edge: command injection
High7.5CVE-2026-86108 · Published Sep 16, 2026 · updated Sep 17, 2026
Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| VeloCloud Edge Product | >= 6.4.0, <= 6.4.1.x | No fix yet |
| >= 6.1.0, <= 6.1.4.x | No fix yet | |
| >= 5.2.0, <= 5.2.6.x | No fix yet | |
| >= 0.0.0, < 5.2.0 | 5.2.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Arista Networks advisories
All Arista Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | Arista Networks EOS: remote code execution | Critical9.2 | No fix yet |
| Sep 16 | Arista Networks EOS: secrets in logs | Medium6.0 | No fix yet |
| Sep 16 | Arista Networks EOS: out-of-bounds read | High7.1 | No fix yet |
| Sep 16 | Arista Networks EOS: secrets in logs | Low2.1 | No fix yet |
| Sep 16 | Arista Networks EOS: denial of service | Medium5.3 | No fix yet |
| Sep 16 | Arista Networks VeloCloud Edge: missing authentication | High8.7 | 5.2.0.0+3 more |