VeloCloud Orchestrator Security Flaw Exposes Internal Functionality
CVE-2026-16812

10CRITICAL

What is CVE-2026-16812?

The VeloCloud Orchestrator, designed for managing enterprise network services, has a security vulnerability that could facilitate unauthorized remote access to its internal functionalities. This concern stems from a design oversight, where certain features, meant solely for internal use, have become accessible externally. If successfully exploited, this vulnerability can compromise the confidentiality, integrity, and availability of sensitive data managed by the orchestrator. VMware has proactively addressed this issue, releasing patches for both hosted and dedicated versions prior to the vulnerability's public disclosure. It is important for users to ensure they are running the updated versions to mitigate the risk of exploitation.

Affected Version(s)

VeloCloud Orchestrator On-Prem 5.2.0 < 5.2.3.14

VeloCloud Orchestrator On-Prem 6.1.0 < 6.1.3.4

VeloCloud Orchestrator On-Prem 6.4.0 < 6.4.2.4

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.