SB2026092335 - Remote code execution in Arista VeloCloud Orchestrator
Published: September 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2026-93952) Exploited
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation in the VeloCloud Orchestrator web interface when handling requests. A remote attacker can send requests to the VeloCloud Orchestrator web interface and execute arbitrary code on the system.
Exploitation requires certificate-based authentication from VeloCloud Edge to VeloCloud Orchestrator to be configured and access to the public portion of the VeloCloud Edge authentication certificate.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install update from vendor's website.