CVE-2026-93952
Received Received - Intake

Authentication Bypass in VeloCloud Orchestrator

Vulnerability report for CVE-2026-93952, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: Arista Networks, Inc.

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
arista vco *
arista velocloud_orchestrator *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in VeloCloud Orchestrator (VCO) on-prem allows a remote attacker to gain access to privileged internal functions. Exploitation could lead to compromise of the VCO host's confidentiality, integrity, and availability, potentially affecting data managed by the orchestrator.

Detection Guidance

Detection requires checking if your VeloCloud Orchestrator (VCO) on-prem version is vulnerable. Verify the installed version against Arista's official patch notes or support portal. No specific commands are provided in the context for detection.

Impact Analysis

If exploited, this vulnerability may allow attackers to take control of the VCO host, leading to unauthorized access, data breaches, or disruption of services. Hosted and Dedicated VCO versions were affected but have been patched.

Compliance Impact

The vulnerability allows remote attackers to access privileged internal functionality, potentially compromising confidentiality, integrity, and availability of the orchestrator and managed data. This could lead to unauthorized access to sensitive information, which may violate GDPR (data protection) and HIPAA (healthcare data privacy) requirements if exploited.

Mitigation Strategies

Immediately apply the official patch provided by Arista for your VCO on-prem version. If hosted or Dedicated versions are affected, contact Arista support for patching. Isolate the VCO host from untrusted networks until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93952. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart