Arista VeloCloud Orchestrator (VCO) On-Prem Improper Input Validation Vulnerability

Release Date: 22nd September 2026 (Added 23 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-93952 is a critical improper input validation vulnerability (CWE-20) in on-premises deployments of Arista Networks VeloCloud Orchestrator (VCO), the management controller for VeloCloud SD-WAN edges. The flaw allows a remote, unauthenticated attacker to access privileged internal functionality and impact the VCO host, compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages.

Reference

  1. https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-93952