Executive brief
Arista VeloCloud Edge is a widely deployed edge networking device used to manage secure WAN connections and branch office traffic. An unauthenticated attacker with access to the internal HA (High Availability) network can execute arbitrary commands with elevated privileges on affected Edge units, potentially taking control of critical network infrastructure and gaining access to sensitive traffic flowing through the device.
Technical details
This vulnerability is a missing authentication vulnerability (CWE-306) in the HA peer communication protocol on VeloCloud Edge devices. An unauthenticated actor with Layer 2 network access to the dedicated HA interconnect can trigger sensitive HA peer functions without verification, bypassing authentication controls. The attack is feasible when HA is enabled and the HA connection is extended through shared switches or VLANs rather than direct port-to-port connections. Successful exploitation results in elevated command execution on the Edge unit, allowing complete device compromise. The vulnerability affects VeloCloud Edge versions 6.4.1.x and below, 6.1.4.x and below, 5.2.6.x and below, and all earlier releases; patches are available in 7.0.0 and later, 6.4.2 and later, 6.1.5.0 and later, and 5.2.7.0 and later.
Affected products
- Arista VeloCloud Edge 6.4.1.x and below, 6.1.4.x and below, 5.2.6.x and below, and all prior releases
Timeline
- 2026-09-09: disclosed: Security Advisory 0179 released
- 2026-09-16: advisory: CVE-2026-86106 published to NVD