Skip to content
Arista NetworksCVE-2026-93952

Arista Networks VeloCloud Orchestrator: remote attacker could access privileged...

Critical9.5CVE-2026-93952 · Published Sep 22, 2026 · updated Sep 23, 2026

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

Arista Networks advisory

Affected versions

PackageAffectedFixed in
VeloCloud Orchestrator (VCO) On-Prem
Product
>= 5.2.0, <= 5.2.3.15No fix yet
>= 6.1.0, <= 6.1.3.7No fix yet
>= 6.4.0, <= 6.4.2.7No fix yet
>= 7.0.0, <= 7.0.0.2No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-20

More Arista Networks advisories

All Arista Networks
Advisory
Arista Networks EOS: remote code execution
Critical9.2Sep 16
Arista Networks EOS: secrets in logs
Medium6.0Sep 16
Arista Networks EOS: out-of-bounds read
High7.1Sep 16
Arista Networks EOS: secrets in logs
Low2.1Sep 16
Arista Networks EOS: denial of service
Medium5.3Sep 16
Arista Networks VeloCloud Edge: missing authentication
High8.7Sep 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.