Description
The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.
Published: 2026-09-16
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Migrating to a patched software version for VeloCloud Edge is the advised course of action. Arista suggests that operators transition to the most recent release within a supported branch that incorporates the necessary remediations.


Vendor Workaround

1. Restrict software-image management and VeloCloud Edge update privileges to trusted administrators. 2. Protect VeloCloud Orchestrator administrative credentials and management access. 3. Obtain and distribute VeloCloud Edge software only through trusted Arista management and distribution channels. 4. Investigate unexpected software images or update operations before permitting installation. These measures reduce exposure but do not correct the vulnerable update-verification workflow.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.
Title Security Advisory 0182
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T02:57:46.285Z

Reserved: 2026-09-05T01:54:43.258Z

Link: CVE-2026-86109

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T03:17:00.250

Modified: 2026-09-16T03:17:00.250

Link: CVE-2026-86109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses