Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The following VeloCloud Edge releases contain the fix: - 5.2.7.0 and later in the 5.2.x train - 6.1.5.0 and later in the 6.1.x train - 6.4.2 and later in the 6.4.x train - 7.0.0 and later No hotfixes are available for this issue.
Vendor Workaround
Use dedicated port-to-port connections between HA pairs. Avoid extending the HA interconnect through shared switches or VLANs. Restrict physical and network access to HA interfaces.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled. | |
| Title | Security Advisory 0179 | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-16T10:25:43.381Z
Reserved: 2026-09-05T01:54:43.258Z
Link: CVE-2026-86106
No data.
Status : Received
Published: 2026-09-16T11:16:43.783
Modified: 2026-09-16T11:16:43.783
Link: CVE-2026-86106
No data.
OpenCVE Enrichment
No data.