CVE-2026-17192
VeloCloud Orchestrator Missing Input Validation SSRF
CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
0th
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
| CWE | CWE-918 |
| Vendor | arista networks |
| Product | velocloud orchestrator on-prem |
| Published | Jul 27, 2026 |
| Last Updated | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for arista networks velocloud orchestrator on-prem
Be the first to know when new high vulnerabilities affecting arista networks velocloud orchestrator on-prem are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
Arista Networks / VeloCloud Orchestrator On-Prem
5.2.0 < 5.2.3.14 6.1.0 < 6.1.3.4 6.4.0 < 6.4.2.4