Security Issue in VeloCloud Orchestrator Affecting Arista
CVE-2026-93952
Key Information:
- Vendor
Arista Networks
- Vendor
- CVE Published:
- 22 September 2026
What is CVE-2026-93952?
A vulnerability in the VeloCloud Orchestrator (VCO) allows remote attackers to potentially gain unauthorized access to sensitive internal functionalities. This could compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. The affected versions include both hosted and dedicated deployments that have since been patched. Organizations using VCO should ensure they have updated to the latest secure versions as recommended in the vendor advisory.
Affected Version(s)
VeloCloud Orchestrator (VCO) On-Prem VeloCloud Orchestrator On-Prem 5.2.0 <= 5.2.3.15
VeloCloud Orchestrator (VCO) On-Prem VeloCloud Orchestrator On-Prem 6.1.0 <= 6.1.3.7
VeloCloud Orchestrator (VCO) On-Prem VeloCloud Orchestrator On-Prem 6.4.0 <= 6.4.2.7
