CVE-2026-93952 is a critical security vulnerability affecting VeloCloud Orchestrator (VCO) On-Prem. It is caused by improper input validation that may allow a remote attacker to access privileged internal functionality and compromise the VCO host. The vulnerability is assigned a CVSS v3.1 score of 10.0 (Critical) and CWE-20: Improper Input Validation. Affected versions include VCO 5.2.3.15 and earlier in the 5.2.x train, 6.1.3.7 and earlier in the 6.1.x train, 6.4.2.7 and earlier in the 6.4.x train, and 7.0.0.2 and earlier in the 7.0.x train. Successful exploitation can impact the confidentiality, integrity, and availability of the orchestrator and data it manages. The vulnerability may also provide attackers with access to privileged functionality on the underlying VCO host. Arista has stated that the issue is actively exploited, increasing the security risk for exposed on-premises deployments.
We recommend you to update VeloCloud Orchestrator on-prem to version 5.2.3.16 or 6.4.2.8.[/subscribe_to_unlock_form]
CVE-2026-93952 is a critical security vulnerability affecting VeloCloud Orchestrator (VCO) On-Prem. It is caused by improper input validation that may allow a remote attacker to access privileged internal functionality and compromise the VCO host. The vulnerability is assigned a CVSS v3.1 score of 10.0 (Critical) and CWE-20: Improper Input Validation. Affected versions include VCO 5.2.3.15 and earlier in the 5.2.x train, 6.1.3.7 and earlier in the 6.1.x train, 6.4.2.7 and earlier in the 6.4.x train, and 7.0.0.2 and earlier in the 7.0.x train. Successful exploitation can impact the confidentiality, integrity, and availability of the orchestrator and data it manages. The vulnerability may also provide attackers with access to privileged functionality on the underlying VCO host. Arista has stated that the issue is actively exploited, increasing the security risk for exposed on-premises deployments.
We recommend you to update VeloCloud Orchestrator on-prem to version 5.2.3.16 or 6.4.2.8.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]