CVE-2026-86108

Summary

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksVeloCloud Edge6.4.0 <= 6.4.1.xaffected
Arista NetworksVeloCloud Edge6.1.0 <= 6.1.4.xaffected
Arista NetworksVeloCloud Edge5.2.0 <= 5.2.6.xaffected
Arista NetworksVeloCloud Edge0.0.0 < 5.2.0affected

Weaknesses

  • CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Workarounds

  1. Restrict VeloCloud Orchestrator Super Admin and Operator roles, particularly Remote Diagnostics and device-configuration access, to trusted personnel.
  2. Protect Orchestrator administrative credentials and management access.
  3. Maintain the default Local UI access restrictions and limit activation access to authorized personnel.

References