SB2026092335 - Remote code execution in Arista VeloCloud Orchestrator



SB2026092335 - Remote code execution in Arista VeloCloud Orchestrator

Published: September 23, 2026

Security Bulletin ID SB2026092335
CSH Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2026-93952) Exploited

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper input validation in the VeloCloud Orchestrator web interface when handling requests. A remote attacker can send requests to the VeloCloud Orchestrator web interface and execute arbitrary code on the system.

Exploitation requires certificate-based authentication from VeloCloud Edge to VeloCloud Orchestrator to be configured and access to the public portion of the VeloCloud Edge authentication certificate.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install update from vendor's website.