View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Critical OS Command Injection in Arista VeloCloud Orchestrator On-Prem

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Critical OS Command Injection in Arista VeloCloud Orchestrator On-Prem (CVE-2026-16812) CVE-2026-16812
    Arista VeloCloud Orchestrator On-Prem has a critical OS command injection vulnerability.
    • Applies to Arista VeloCloud Orchestrator On-Prem versions before 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1
    • Vulnerability allows remote attackers to execute OS commands and access privileged internal functions
    • Exploitation compromises confidentiality, integrity, and availability of the orchestrator and managed data
    • Attack vector is remote network access exploiting internal-use functionality not intended for remote exposure
    • Hosted and Dedicated VCO versions were patched prior to public disclosure; on-premises versions remain vulnerable
      ๐Ÿ“Ž Coverage: arista.com ยท ๐Ÿ“„ Original: arista.com ยท ๐Ÿ‘ via CISA KEV

๐Ÿ”“ CVEs & KEV

  • Other: 20 CVEs (worst 7.8)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check