Back to overview

CVE-2026-17191

CRITICAL
9.1
CVSS 3.1
Description
An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

Metadata

CVE ID
CVE-2026-17191
State
PUBLISHED
Assigner
Arista
Reserved
2026-07-24 19:03 UTC
Published
2026-07-27 16:41 UTC
Last updated
2026-07-27 17:29 UTC
Primary CWE
CWE-89
CWE-89 Improper Neutralization of Special Elements used in a…
Vendor / Product
Arista Networks / VeloCloud Orchestrator On-Prem
Sources
cve.org  ·  NVD

Severity & Metrics

9.1 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Arista Networks VeloCloud Orchestrator On-Prem 5.2.0 < 5.2.3.14, 6.1.0 < 6.1.3.4, 6.4.0 < 6.4.2.4
Weakness (CWE)
CWESourceDescription
CWE-89 cna CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.1 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
8.5 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/S:P
Back to overview