Junglewise Threat Intelligence

CVE-2026-86108: Arista VeloCloud Edge OS command injection in management workflows

CVE-2026-86108 · Severity: high · CVSS 8 · Published 2026-09-16

Executive brief

VeloCloud Edge is a wide-area network (WAN) edge appliance that manages network connections and traffic for distributed enterprises. An input validation flaw in its management and configuration interfaces allows authorized administrators with access to the management plane to inject operating-system commands that execute with elevated privileges. Successful exploitation could give attackers complete control over affected edge devices, potentially compromising all network traffic and data passing through them.

Technical details

This is an OS command injection vulnerability (CWE-78) in VeloCloud Edge's management and configuration workflows. Insufficient input validation on parameters passed through management requests or configuration values allows them to be interpreted as operating-system commands. The vulnerability requires the attacker to either control a compromised VeloCloud Orchestrator (management server) or possess valid administrative credentials to submit malicious parameters through the management interface. Exploitation results in command execution with elevated privileges on the edge device. The flaw was discovered internally by Arista and is not known to be exploited in the wild. Patched versions are available: 7.0.0+, 6.4.2+, 6.1.5.0+, and 5.2.7.0+.

Affected products

  • Arista VeloCloud Edge 6.4.1.x and below in 6.4.x train; 6.1.4.x and below in 6.1.x train; 5.2.6.x and below in 5.2.x train; all prior releases

Timeline

  • 2026-09-09: disclosed: Initial advisory release
  • 2026-09-16: disclosed: CVE published
  • 2026-09-22: other: CSAF JSON file added to advisory

References

Related threats