CVE-2026-17191
Received Received - Intake

Orchestrator API Input Validation Flaw Leads to Unauthorized Access

Vulnerability report for CVE-2026-17191, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Arista Networks, Inc.

Description

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista orchestrator *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an input validation vulnerability in an API component of the orchestrator. An authenticated user can exploit it to manipulate backend queries, potentially gaining unauthorized access to data beyond their privileges and causing the system to initiate unintended outbound network connections.

Detection Guidance

Detection requires monitoring API traffic for unusual query patterns or unauthorized data access attempts. Check logs for outbound connections initiated by the orchestrator. Review user authentication logs for suspicious activity. No specific commands are provided in the context.

Impact Analysis

An attacker could access sensitive data they shouldn't, modify system behavior, or trigger unexpected network activity. This may lead to data breaches, system instability, or compliance violations depending on the data involved.

Compliance Impact

This vulnerability could lead to unauthorized data access, which may violate GDPR (data protection) or HIPAA (health data privacy) requirements. Organizations using affected systems may face compliance penalties or legal consequences if exploited.

Mitigation Strategies

Apply patches or updates from Arista if available. Restrict API access to trusted users only. Monitor network traffic for unexpected outbound connections. Review and tighten user privilege levels in the orchestrator.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17191. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart