CVE-2026-86109
Security Advisory 0182
CVSS Score
6.6
EPSS Score
0.0%
EPSS Percentile
0th
The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.
| CWE | CWE-347 |
| Vendor | arista networks |
| Product | velocloud edge |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for arista networks velocloud edge
Be the first to know when new medium vulnerabilities affecting arista networks velocloud edge are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Arista Networks / VeloCloud Edge
6.4.0 โค 6.4.1.x 6.1.0 โค 6.1.4.x 5.2.0 โค 5.2.6.x 0.0.0 < 5.2.0
References
Credits
This issue was discovered internally by Arista. Arista is not aware of any malicious exploitation of this vulnerability in customer networks.