CVE-2026-86106

Summary

An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksVeloCloud Edge1.0.0.0 < 5.2.0.0affected
Arista NetworksVeloCloud Edge5.2.0.0 < 5.2.7.0affected
Arista NetworksVeloCloud Edge6.1.0.0 < 6.1.5.0affected
Arista NetworksVeloCloud Edge6.4.0.0 < 6.4.2.0affected

Weaknesses

  • CWE-306: CWE-306 Missing Authentication for Critical Function

Workarounds

Use dedicated port-to-port connections between HA pairs. Avoid extending the HA interconnect through shared switches or VLANs. Restrict physical and network access to HA interfaces.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References