Threat Advisory

VeloCloud Orchestrator Vulnerability Enables Command Injection

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-16812 with a CVSS score of 10.0 is a critical security flaw impacting the Arista VeloCloud Orchestrator On-Prem software used for managing SD-WAN environments. This vulnerability affects versions prior to the updates released in 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. It is an OS command injection vulnerability that permits an unauthenticated remote attacker to interact with privileged internal functionality that was never intended to be exposed externally. Exploitation requires only access to the exposed web interface, which is accessible by default on on-premises deployments, and does not require valid user credentials. A successful attacker can gain the ability to execute arbitrary commands with high privileges, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data. This poses severe operational risks, as attackers could leverage the compromised orchestrator to pivot and access managed VeloCloud Edge devices, leading to widespread network disruption or unauthorized data access. Exploitation is contingent upon the attacker having network connectivity to the vulnerable web interface, which cannot be fully removed through configuration.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-16812 with a CVSS score of 10.0 is a critical security flaw impacting the Arista VeloCloud Orchestrator On-Prem software used for managing SD-WAN environments. This vulnerability affects versions prior to the updates released in 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. It is an OS command injection vulnerability that permits an unauthenticated remote attacker to interact with privileged internal functionality that was never intended to be exposed externally. Exploitation requires only access to the exposed web interface, which is accessible by default on on-premises deployments, and does not require valid user credentials. A successful attacker can gain the ability to execute arbitrary commands with high privileges, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data. This poses severe operational risks, as attackers could leverage the compromised orchestrator to pivot and access managed VeloCloud Edge devices, leading to widespread network disruption or unauthorized data access. Exploitation is contingent upon the attacker having network connectivity to the vulnerable web interface, which cannot be fully removed through configuration.[emaillocker id="1283"]

RECOMMENDATION:

  • We recommend you to update VeloCloud Orchestrator to version 5.2.3.14.
  • We recommend you to update VeloCloud Orchestrator to version 6.1.3.4.
  • We recommend you to update VeloCloud Orchestrator to version 6.4.2.4.
  • We recommend you to update VeloCloud Orchestrator to version 7.0.0.1.

REFERENCES:

The following reports contain further technical details:
https://www.theregister.com/security/2026/07/28/arista-patches-actively-exploited-velocloud-bug-as-cisa-puts-admins-on-the-clock/5279414

[/emaillocker]
crossmenu