Back to overview

CVE-2026-17192

HIGH
8.5
CVSS 3.1
Description
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

Metadata

CVE ID
CVE-2026-17192
State
PUBLISHED
Assigner
Arista
Reserved
2026-07-24 19:03 UTC
Published
2026-07-27 16:36 UTC
Last updated
2026-07-27 17:28 UTC
Primary CWE
CWE-918
CWE-918 Server-Side Request Forgery (SSRF)
Vendor / Product
Arista Networks / VeloCloud Orchestrator On-Prem
Sources
cve.org  ·  NVD

Severity & Metrics

8.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Arista Networks VeloCloud Orchestrator On-Prem 5.2.0 < 5.2.3.14, 6.1.0 < 6.1.3.4, 6.4.0 < 6.4.2.4
Weakness (CWE)
CWESourceDescription
CWE-918 cna CWE-918 Server-Side Request Forgery (SSRF)
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
6.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/S:P
Back to overview