CVE-2026-86108
Security Advisory 0181
CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th
Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
| CWE | CWE-78 |
| Vendor | arista networks |
| Product | velocloud edge |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for arista networks velocloud edge
Be the first to know when new high vulnerabilities affecting arista networks velocloud edge are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Arista Networks / VeloCloud Edge
6.4.0 โค 6.4.1.x 6.1.0 โค 6.1.4.x 5.2.0 โค 5.2.6.x 0.0.0 < 5.2.0
References
Credits
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.