Arista NetworksCVE-2026-86109
Arista Networks VeloCloud Edge: improper signature check
High7.5CVE-2026-86109 · Published Sep 16, 2026 · updated Sep 17, 2026
The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| VeloCloud Edge Product | >= 6.4.0, <= 6.4.1.x | No fix yet |
| >= 6.1.0, <= 6.1.4.x | No fix yet | |
| >= 5.2.0, <= 5.2.6.x | No fix yet | |
| >= 0.0.0, < 5.2.0 | 5.2.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-347
More Arista Networks advisories
All Arista Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | Arista Networks EOS: remote code execution | Critical9.2 | No fix yet |
| Sep 16 | Arista Networks EOS: secrets in logs | Medium6.0 | No fix yet |
| Sep 16 | Arista Networks EOS: out-of-bounds read | High7.1 | No fix yet |
| Sep 16 | Arista Networks EOS: secrets in logs | Low2.1 | No fix yet |
| Sep 16 | Arista Networks EOS: denial of service | Medium5.3 | No fix yet |
| Sep 16 | Arista Networks VeloCloud Edge: missing authentication | High8.7 | 5.2.0.0+3 more |