This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
The recommended resolution is to upgrade to a fixed VCO release at your earliest convenience. These vulnerabilities have been fixed in the following releases: * VCO 5.2.3.14 and later in the 5.2 train * VCO 6.1.3.4 and later in the 6.1 train * VCO 6.4.2.4 and later in the 6.4 train
Workaround
The recommended resolution is to upgrade to a fixed VCO release as soon as it is available. For VCOs which are not on a supported release train, customers can contact TAC to discuss possible upgrade options for your release. Until the fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment: * Restrict access to the VCO web interface to trusted administrative networks. * Monitor the VCO for accesses from known malicious source IPs. * Monitor for unexpected outbound network activity from the VCO host. * Review recent administrator activity for unexpected changes.
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arista Networks
Arista Networks velocloud Orchestrator On-prem |
|
| Vendors & Products |
Arista Networks
Arista Networks velocloud Orchestrator On-prem |
Mon, 27 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. | |
| Title | VeloCloud Orchestrator Missing Input Validation SSRF | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-07-27T17:28:36.203Z
Reserved: 2026-07-24T19:03:16.141Z
Link: CVE-2026-17192
Updated: 2026-07-27T17:28:32.954Z
Status : Awaiting Analysis
Published: 2026-07-27T17:16:35.573
Modified: 2026-07-30T19:10:52.250
Link: CVE-2026-17192
No data.
OpenCVE Enrichment
Updated: 2026-08-03T17:15:12Z