CVE-2026-16812
Received Received - Intake

Remote Code Execution in VeloCloud Orchestrator

Vulnerability report for CVE-2026-16812, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Arista Networks, Inc.

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
arista vco *
arista velocloud_orchestrator *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in VeloCloud Orchestrator (VCO) on-prem allows a remote attacker to access privileged internal functionality that was never meant to be exposed externally. Successful exploitation could compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized remote access to the VeloCloud Orchestrator (VCO) on-prem. Monitor network traffic for unexpected connections to internal VCO ports. Inspect logs for unusual administrative access attempts or privileged operations performed remotely.

Impact Analysis

An attacker could exploit this to gain control over the VCO host, potentially leading to unauthorized access, data breaches, or disruption of services. Since the issue is actively exploited, the risk of impact is high if the system is not patched.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR (data protection) and HIPAA (healthcare data privacy) requirements. Non-compliance risks include legal penalties, fines, and reputational damage.

Mitigation Strategies

Immediately restrict external access to the VCO on-prem management interface. Apply network-level controls to block unauthorized remote access. Contact Arista support for patch availability or isolation of the affected system until a patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16812. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart