CVE-2026-86108
8
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Summary
Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | VeloCloud Edge | 6.4.0 <= 6.4.1.x | affected |
| Arista Networks | VeloCloud Edge | 6.1.0 <= 6.1.4.x | affected |
| Arista Networks | VeloCloud Edge | 5.2.0 <= 5.2.6.x | affected |
| Arista Networks | VeloCloud Edge | 0.0.0 < 5.2.0 | affected |
Weaknesses
- CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Workarounds
- Restrict VeloCloud Orchestrator Super Admin and Operator roles, particularly Remote Diagnostics and device-configuration access, to trusted personnel.
- Protect Orchestrator administrative credentials and management access.
- Maintain the default Local UI access restrictions and limit activation access to authorized personnel.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.