Input Validation Flaw in Arista's API Component Leads to Data Access Issues
CVE-2026-17191

8.5HIGH

What is CVE-2026-17191?

An input validation flaw exists in the API component of Arista's Orchestrator that allows authenticated users to exploit the system. By manipulating backend queries, users may gain unauthorized access to data that exceeds their privileges. This vulnerability has the potential to trigger unintended outbound network connections, posing significant risks to the integrity and security of the network. Currently, Arista has stated that they are not aware of any malicious exploitation of this issue in customer environments.

Affected Version(s)

VeloCloud Orchestrator On-Prem 5.2.0 < 5.2.3.14

VeloCloud Orchestrator On-Prem 6.1.0 < 6.1.3.4

VeloCloud Orchestrator On-Prem 6.4.0 < 6.4.2.4

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.