← Back to CVE List
Vulnerability Intelligence Report
VeloCloud Orchestrator Flow Metrics API SQL Injection

CVE-2026-17191

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

Injection No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.2
Impact Score:5.3
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-89 ↗CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Affected Products & Versions

Vendor Product Affected Versions
Arista Networks VeloCloud Orchestrator On-Prem 5.2.0 < 5.2.3.14 (affected), 6.1.0 < 6.1.3.4 (affected), 6.4.0 < 6.4.2.4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Vulnerability Class
Injection

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityArista Networks, Inc. · Vendor · USA
Reserved2026-07-24T19:03:13
Published2026-07-27T16:41:17
Patch Date2026-07-27
Last Updated2026-07-27T17:29:45

LINK COPIED TO CLIPBOARD