cbcvebase.

Arista Networks Velocloud Orchestrator On-Prem vulnerabilities

3 known vulnerabilities affecting arista_networks/velocloud_orchestrator_on-prem.

Total CVEs
3
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH1

Vulnerabilities

Page 1 of 1
CVE-2026-16812P1CRITICALCVSS 10.0KEV≥ 5.2.0, < 5.2.3.14≥ 6.1.0, < 6.1.3.4+2 more2026-07-27
CVE-2026-16812 [CRITICAL] CWE-78 CVE-2026-16812: VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attack VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intende
nvd
CVE-2026-17191P2CRITICALCVSS 9.1≥ 5.2.0, < 5.2.3.14≥ 6.1.0, < 6.1.3.4+1 more2026-07-27
CVE-2026-17191 [CRITICAL] CWE-89 CVE-2026-17191: An input validation vulnerability exists in an API component of the orchestrator. An authenticated u An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered
nvd
CVE-2026-17192P3HIGHCVSS 8.5≥ 5.2.0, < 5.2.3.14≥ 6.1.0, < 6.1.3.4+1 more2026-07-27
CVE-2026-17192 [HIGH] CWE-918 CVE-2026-17192: A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any
nvd
Arista Networks Velocloud Orchestrator On-Prem vulnerabilities | cvebase