Arista VeloCloud Orchestrator (VCO) On-Prem Improper Input Validation Vulnerability
Release Date: 22nd September 2026 (Added 23 September 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-93952 is a critical improper input validation vulnerability (CWE-20) in on-premises deployments of Arista Networks VeloCloud Orchestrator (VCO), the management controller for VeloCloud SD-WAN edges. The flaw allows a remote, unauthenticated attacker to access privileged internal functionality and impact the VCO host, compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages.
What are the systems affected?
The following on-premises VeloCloud Orchestrator (VCO) releases are affected:
- VCO 5.2.3.15 and earlier (5.2.x train)
- VCO 6.1.3.7 and earlier (6.1.x train)
- VCO 6.4.2.7 and earlier (6.4.x train)
- VCO 7.0.0.2 and earlier (7.0.x train)
Not affected / patched version:
- VCO 5.2.3.16 and later, and VCO 6.4.2.8 and later. Arista states fixes for the 6.1.x and 7.0.x trains are still to follow at time of writing - confirm current availability directly with Arista before relying on an unpatched train. Arista-hosted and dedicated VCO instances were already patched by Arista and require no customer action.
What does this mean?
Successful exploitation may allow attackers to:
- Access privileged internal functionality on the VCO host without any valid credentials, where certificate-based Edge authentication is configured
- Compromise the confidentiality, integrity, and availability of the orchestrator and the SD-WAN configuration data it manages
- Deploy backdoor daemons or webshells on the VCO host, based on indicators of compromise Arista has published from confirmed intrusions
Mitigation process?
CERTVU recommends the following:
-
Apply the vendor patch as an emergency change
Upgrade on-premises VCO instances to 5.2.3.16 or later, or 6.4.2.8 or later, as applicable. For the 6.1.x or 7.0.x trains, contact Arista for the current fix status and apply it as soon as it is available. -
Restrict network access to the VCO web interface
Limit access to the VCO web-management interface to trusted administrative networks only, given this flaw is remotely reachable and requires no VCO credentials. -
Review for indicators of compromise
Reference
- https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-93952
- Download advisory (English): Arista VeloCloud Orchestrator (VCO) On-Prem Improper Input Validation Vulnerability