CVE-2026-86109

Summary

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksVeloCloud Edge6.4.0 <= 6.4.1.xaffected
Arista NetworksVeloCloud Edge6.1.0 <= 6.1.4.xaffected
Arista NetworksVeloCloud Edge5.2.0 <= 5.2.6.xaffected
Arista NetworksVeloCloud Edge0.0.0 < 5.2.0affected

Weaknesses

  • CWE-347: CWE-347: Improper Verification of Cryptographic Signature

Workarounds

  1. Restrict software-image management and VeloCloud Edge update privileges to trusted administrators.
  2. Protect VeloCloud Orchestrator administrative credentials and management access.
  3. Obtain and distribute VeloCloud Edge software only through trusted Arista management and distribution channels.
  4. Investigate unexpected software images or update operations before permitting installation. These measures reduce exposure but do not correct the vulnerable update-verification workflow.

References