Security
Loading…

CVE-2026-16812

CRITICALCVSS 10.0Known Exploited
Description

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Timeline
Published:July 27th, 2026 4:17 PM
Last modified:July 28th, 2026 2:50 PM
Added to KEV:July 27th, 2026
CVSS Scoring

CVSS v3: 10.0 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

arista

Products

velocloud_orchestrator
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute