Security Issue in VeloCloud Orchestrator Affecting Arista
CVE-2026-93952

9.5CRITICAL

What is CVE-2026-93952?

A vulnerability in the VeloCloud Orchestrator (VCO) allows remote attackers to potentially gain unauthorized access to sensitive internal functionalities. This could compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. The affected versions include both hosted and dedicated deployments that have since been patched. Organizations using VCO should ensure they have updated to the latest secure versions as recommended in the vendor advisory.

Affected Version(s)

VeloCloud Orchestrator (VCO) On-Prem VeloCloud Orchestrator On-Prem 5.2.0 <= 5.2.3.15

VeloCloud Orchestrator (VCO) On-Prem VeloCloud Orchestrator On-Prem 6.1.0 <= 6.1.3.7

VeloCloud Orchestrator (VCO) On-Prem VeloCloud Orchestrator On-Prem 6.4.0 <= 6.4.2.7

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.