Junglewise Threat Intelligence

CVE-2026-16812: Arista VeloCloud Orchestrator OS command injection in on-prem host

CVE-2026-16812 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-07-27

Technologies: Arista Networks VeloCloud Orchestrator On-Prem. Vendors: Arista Networks.

Executive brief

Arista VeloCloud Orchestrator is a management platform used to control and monitor SD-WAN network infrastructure. A critical security flaw allows unauthorized remote attackers to execute commands on the system, potentially leading to a full takeover of the orchestrator. This could result in the theft of sensitive network data, disruption of corporate connectivity, and unauthorized changes to network configurations.

Technical details

An OS command injection vulnerability (CWE-78) exists in Arista VeloCloud Orchestrator (VCO) On-Prem due to improper neutralization of special elements in internal functionality that was unintentionally exposed to remote access. The vulnerability is network-reachable and requires no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). Successful exploitation allows an attacker to execute arbitrary commands on the VCO host with high privileges, leading to a complete compromise of confidentiality, integrity, and availability. Arista has released patches for affected versions, and hosted/dedicated versions were patched prior to public disclosure. This vulnerability is known to be actively exploited.

Affected products

  • Arista Networks VeloCloud Orchestrator On-Prem 5.2.0 < 5.2.3.14, 6.1.0 < 6.1.3.4, 6.4.0 < 6.4.2.4, 7.0.0 < 7.0.0.1

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory
  • 2026-07-27: exploited: Reported as actively exploited at the time of disclosure.

Related threats