Input Validation Flaw in Arista's API Component Leads to Data Access Issues
CVE-2026-17191
8.5HIGH
Key Information:
- Vendor
Arista Networks
- Vendor
- CVE Published:
- 27 July 2026
What is CVE-2026-17191?
An input validation flaw exists in the API component of Arista's Orchestrator that allows authenticated users to exploit the system. By manipulating backend queries, users may gain unauthorized access to data that exceeds their privileges. This vulnerability has the potential to trigger unintended outbound network connections, posing significant risks to the integrity and security of the network. Currently, Arista has stated that they are not aware of any malicious exploitation of this issue in customer environments.
Affected Version(s)
VeloCloud Orchestrator On-Prem 5.2.0 < 5.2.3.14
VeloCloud Orchestrator On-Prem 6.1.0 < 6.1.3.4
VeloCloud Orchestrator On-Prem 6.4.0 < 6.4.2.4
