Known vulnerabilities in VeloCloud Orchestrator (VCO)

Software CPE: cpe:2.3:a:arista:velocloud_orchestrator_vco:*:*:*:*:*:*:*:*
Total vulnerabilities: 3
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting VeloCloud Orchestrator (VCO) VeloCloud Orchestrator (VCO) is affected by 3 known vulnerabilities: 1 high, 2 medium Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140095 - Server-Side Request Forgery (SSRF)
CVE-2026-17192
CWE-918 Medium
No
No
5.2.3.14, 6.1.3.4, 6.4.2.4 30.07.2026 SB2026073026
#VU140092 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-17191
CWE-89 Medium
No
No
5.2.3.14, 6.1.3.4, 6.4.2.4 30.07.2026 SB2026073026
#VU140091 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-16812
CWE-78 High
No
Exploited
5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1 30.07.2026 SB2026073026