๐Ÿ” CVE Alert

CVE-2026-86109

MEDIUM 6.6

Security Advisory 0182

CVSS Score
6.6
EPSS Score
0.0%
EPSS Percentile
0th

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.

CWE CWE-347
Vendor arista networks
Product velocloud edge
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for arista networks velocloud edge

Be the first to know when new medium vulnerabilities affecting arista networks velocloud edge are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Arista Networks / VeloCloud Edge
6.4.0 โ‰ค 6.4.1.x 6.1.0 โ‰ค 6.1.4.x 5.2.0 โ‰ค 5.2.6.x 0.0.0 < 5.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
arista.com: https://www.arista.com/zh/support/advisories-notices/security-advisory/24738-security-advisory-0182

Credits

This issue was discovered internally by Arista. Arista is not aware of any malicious exploitation of this vulnerability in customer networks.