← Back to CVE List
CVE-2026-17192NVD
Vulnerability Summary
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin.
This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
CVSS v4.0 Base Metrics — Score 6.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)None
Confidentiality (Subsequent System)High
Integrity (Subsequent System)Low
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 8.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- Arista Networks VeloCloud Orchestrator On-Prem >= 5.2.0 and < 5.2.3.14
- Arista Networks VeloCloud Orchestrator On-Prem >= 6.1.0 and < 6.1.3.4
- Arista Networks VeloCloud Orchestrator On-Prem >= 6.4.0 and < 6.4.2.4
- Arista Networks VeloCloud Orchestrator On-Prem 5.2.3.14
- Arista Networks VeloCloud Orchestrator On-Prem 6.1.3.4
- Arista Networks VeloCloud Orchestrator On-Prem 6.4.2.4