Full Report
Unauthenticated command injection scores perfect 10 and may expose managed Edge devices
Analysis Summary
# Vulnerability: Unauthenticated Command Injection in Arista VeloCloud Orchestrator
## CVE Details
- **CVE ID:** CVE-2026-16812
- **CVSS Score:** 10.0 (Critical)
- **CWE:** OS Command Injection
## Affected Systems
- **Products:** VeloCloud Orchestrator (VCO)
- **Versions:** On-premises, self-hosted deployments running versions prior to:
- 5.2.3.14
- 6.1.3.4
- 6.4.2.4
- 7.0.0.1
- **Configurations:** This affects "On-Prem" versions. Per the advisory, the vulnerable interface is exposed by default, and no configuration can entirely remove this exposure without patching.
## Vulnerability Description
CVE-2026-16812 is an OS command injection vulnerability located within the VeloCloud Orchestrator's web interface. The flaw allows an unauthenticated remote attacker to access privileged internal functionality that was intended only for internal use. By sending specially crafted requests to the web management interface, an attacker can execute arbitrary commands at the operating system level.
## Exploitation
- **Status:** **Exploited in the wild.** Added to CISA KEV catalog as of July 2026.
- **Complexity:** Low (Requires only access to the web interface; no credentials needed).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** Total (Full access to orchestrator data and potential access to managed Edge devices).
- **Integrity:** Total (Ability to modify data and configurations across the SD-WAN).
- **Availability:** Total (Potential for complete system takeover or service disruption).
## Remediation
### Patches
Arista recommends upgrading to the following versions immediately:
- **5.2.3.14**
- **6.1.3.4**
- **6.4.2.4**
- **7.0.0.1**
*Note: Hosted/Cloud-based VeloCloud Orchestrator services have already been patched by Arista.*
### Workarounds
- **Network Segmentation:** Restrict access to the VCO web management interface to trusted management networks only.
- **IP Filtering:** Block traffic from known malicious IP addresses (see Detection section).
- **External Exposure:** Ensure the management interface is not reachable over the public internet.
## Detection
- **Indicators of Compromise:** Arista has identified three IP addresses observed in active exploitation (specific IPs were not listed in the article text but are included in the vendor advisory).
- **Detection Methods:** Monitor web server logs for unusual requests directed at privileged internal management endpoints. Review CISA KEV updates for additional forensic details.
## References
- Arista Security Advisory 0144: hxxps[://]www[.]arista[.]com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
- CISA Known Exploited Vulnerabilities Catalog: hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog