CVE-2026-86106
9.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | VeloCloud Edge | 1.0.0.0 < 5.2.0.0 | affected |
| Arista Networks | VeloCloud Edge | 5.2.0.0 < 5.2.7.0 | affected |
| Arista Networks | VeloCloud Edge | 6.1.0.0 < 6.1.5.0 | affected |
| Arista Networks | VeloCloud Edge | 6.4.0.0 < 6.4.2.0 | affected |
Weaknesses
- CWE-306: CWE-306 Missing Authentication for Critical Function
Workarounds
Use dedicated port-to-port connections between HA pairs. Avoid extending the HA interconnect through shared switches or VLANs. Restrict physical and network access to HA interfaces.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.