Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

🚨SEVERITY: CRITICAL — CVSS 10.0Security Advisory

TL;DR 📌

  • Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
  • Highest CVSS: 10.0 (Critical).
  • Listed in CISA KEV (2026-09-22) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-93952.

What it is

CVE-2026-93952 is an improper input validation flaw in Arista’s VeloCloud Orchestrator (VCO), specifically the on-prem deployment. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the flaw is reachable over the network, requires no authentication, no user interaction, and has low attack complexity. Arista’s own description states that successful exploitation may allow a remote attacker to access privileged internal functionality on the VCO host.

The scope-changed vector (S:C) combined with full impact on confidentiality, integrity and availability (C:H/I:H/A:H) points to an attacker being able to move beyond the vulnerable component itself and affect the underlying host and the data the orchestrator manages. VCO is the management plane for VeloCloud SD-WAN deployments, so compromise here has implications for the SD-WAN fabric it controls, not just the orchestrator application.

Arista notes that Hosted and Dedicated versions of VCO were also affected but have already been patched by Arista directly. The exposure described here concerns on-prem installations, which remain the operator’s responsibility to remediate.

The flaw is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 22 September 2026, so it is known to be exploited.

What to do

  • Identify any on-prem VeloCloud Orchestrator instances in your estate — Hosted and Dedicated deployments have already been remediated by Arista and do not need separate action.
  • Consult Arista’s advisory for the specific fixed release for on-prem VCO; no fixed version number has been confirmed here, so do not assume a particular build is safe without checking directly.
  • Given the unauthenticated, network-reachable nature of this flaw, restrict access to the VCO management interface to trusted networks only, pending patching — do not rely on network segmentation alone as a long-term fix.
  • Because this CVE is in CISA’s KEV catalogue, treat remediation as time-critical if you are subject to CISA Binding Operational Directive 22-01 or equivalent internal policy.
  • After patching, review VCO logs and any exposed management endpoints for signs of anomalous access predating the fix, given the CIA-complete impact profile of this vulnerability.

For leadership 🧭

Executive summary. A maximum-severity, unauthenticated flaw in on-prem VeloCloud Orchestrator lets a remote attacker take over the management plane controlling your SD-WAN fabric, and it is already listed as exploited in the wild. Any on-prem VCO instance should be treated as needing emergency remediation this week, not at the next scheduled change window.

Why it matters:

  • VeloCloud Orchestrator is the central management plane for the SD-WAN fabric; compromise here extends beyond the orchestrator itself to the devices and traffic it controls.
  • The flaw needs no credentials and no user interaction, and is reachable over the network with low attack complexity, so any internet- or corporate-network-exposed VCO management interface is a viable entry point.
  • The scope-changed, CIA-complete impact means an attacker can move beyond the vulnerable component to affect the underlying host and the data the orchestrator manages, not just the application.
  • Inclusion in CISA’s KEV catalogue since 22 September 2026 confirms this is being actively exploited, not a theoretical weakness.

Now / Next / Later:

  • Now: Inventory every on-prem VeloCloud Orchestrator instance and immediately restrict access to its management interface to trusted networks only, since Hosted and Dedicated versions are already patched by Arista and need no action.
  • Next: Apply Arista’s fixed release for on-prem VCO as soon as it is confirmed for your version, treating this as a KEV-driven emergency change rather than routine patching.
  • Later: Establish standing network-level restrictions on SD-WAN orchestrator management interfaces and a routine for reviewing VCO logs after any future patch, so exposure isn’t dependent on catching each advisory individually.

Source