CVE-2026-16812 – Arista Networks VeloCloud Orchestrator On-Prem
“An internal feature exposed to the internet can quickly become an attacker's fastest path to full compromise.”
This patch addresses CVE-2026-16812, a critical vulnerability affecting Arista Networks VeloCloud Orchestrator On-Prem. The flaw allows a remote attacker to access privileged internal functionality that was intended for internal use only. Successful exploitation can impact the VCO host and compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. Hosted and Dedicated versions of VCO were patched before this advisory was released.
The CVSS score is 10.0, which is Critical severity. Active exploitation has been confirmed. The vulnerability also enables remote code execution (RCE), making this an urgent patching priority for organizations running on-premises VeloCloud Orchestrator deployments.
Key Details
- Affected Product
- Arista Velocloud Orchestrator
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-78