Input validation error in VeloCloud Orchestrator (VCO) - CVE-2026-93952

 

Input validation error in VeloCloud Orchestrator (VCO) - CVE-2026-93952

Published: September 23, 2026


Vulnerability identifier: #VU151803
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93952
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the confidentiality, integrity, and availability of the VeloCloud Orchestrator and data managed by it.

The vulnerability exists due to improper input validation in the VeloCloud Orchestrator web interface when handling requests. A remote attacker can send requests to the VeloCloud Orchestrator web interface to compromise the confidentiality, integrity, and availability of the VeloCloud Orchestrator and data managed by it.

Exploitation requires certificate-based authentication from VeloCloud Edge to VeloCloud Orchestrator to be configured and access to the public portion of the VeloCloud Edge authentication certificate.


Affected software

VeloCloud Orchestrator (VCO)

How to mitigate CVE-2026-93952

Install security update from vendor's website.

VeloCloud Orchestrator (VCO) - addressed in versions 5.2.3.16, 6.4.2.8

External References