Input validation error in VeloCloud Orchestrator (VCO) - CVE-2026-93952
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the confidentiality, integrity, and availability of the VeloCloud Orchestrator and data managed by it.
The vulnerability exists due to improper input validation in the VeloCloud Orchestrator web interface when handling requests. A remote attacker can send requests to the VeloCloud Orchestrator web interface to compromise the confidentiality, integrity, and availability of the VeloCloud Orchestrator and data managed by it.
Exploitation requires certificate-based authentication from VeloCloud Edge to VeloCloud Orchestrator to be configured and access to the public portion of the VeloCloud Edge authentication certificate.