Junglewise Threat Intelligence

CVE-2026-17192: Arista VeloCloud Orchestrator SSRF due to missing input validation

CVE-2026-17192 · Severity: high · CVSS 8.5 · Published 2026-07-27

Technologies: Arista Networks VeloCloud Orchestrator On-Prem. Vendors: Arista Networks.

Executive brief

Arista VeloCloud Orchestrator, a platform used to manage SD-WAN networks, contains a vulnerability that allows authorized administrative users to bypass security boundaries. By exploiting this flaw, an attacker with existing 'Enterprise Standard Admin' credentials can force the system to make unauthorized requests to internal services that are normally protected. This could lead to the exposure of sensitive internal data or further access into the corporate network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Arista VeloCloud Orchestrator (VCO) On-Prem due to insufficient validation of caller-supplied input within a specific feature. An attacker with a valid session and a minimum role of 'Enterprise Standard Admin' can submit crafted requests that the orchestrator will execute on their behalf. This allows the attacker to reach internal services and network resources that are otherwise inaccessible from the external network. The vulnerability is tracked as BUG 1568526 and has been patched in versions 5.2.3.14, 6.1.3.4, and 6.4.2.4.

Affected products

  • Arista Networks VeloCloud Orchestrator On-Prem 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4

Timeline

  • 2026-07-27: disclosed: Discovered internally by Arista
  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats