Vulnerability intelligence
CVE-2026-17192
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
CVSS Score
8.5
High
EPSS — Exploit Probability
2.3%
Riskier than 83% of all CVEs · checked 2026-09-10
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jul 27, 2026 · latest Jul 27, 2026
Coverage timeline
-
Arista Warns of Actively Exploited VeloCloud Orchestrator Bugsecurityonline.info · Jul 27, 2026