← Back to CVE List
Vulnerability Intelligence Report
Security Advisory 0183

CVE-2026-93952

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:0.42%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-20 ↗CWE-20 Improper Input Validation

Affected Products & Versions

Vendor Product Affected Versions
Arista Networks VeloCloud Orchestrator (VCO) On-Prem 5.2.0 <= 5.2.3.15 (affected), 6.1.0 <= 6.1.3.7 (affected), 6.4.0 <= 6.4.2.7 (affected), 7.0.0 <= 7.0.0.2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.424%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityArista Networks, Inc. · Vendor · USA
Reserved2026-09-19T01:37:47
Published2026-09-22T07:37:24
Last Updated2026-09-22T13:14:07

LINK COPIED TO CLIPBOARD