Description
Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
Published: 2026-09-16
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Migrating to a patched software version for VeloCloud Edge is the advised course of action. Arista suggests that operators transition to the most recent release within a supported branch that incorporates the necessary remediations.


Vendor Workaround

1. Restrict VeloCloud Orchestrator Super Admin and Operator roles, particularly Remote Diagnostics and device-configuration access, to trusted personnel. 2. Protect Orchestrator administrative credentials and management access. 3. Maintain the default Local UI access restrictions and limit activation access to authorized personnel.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
Title Security Advisory 0181
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T02:50:07.219Z

Reserved: 2026-09-05T01:54:43.258Z

Link: CVE-2026-86108

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T03:17:00.077

Modified: 2026-09-16T03:17:00.077

Link: CVE-2026-86108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses