CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Summary
Arista VeloCloud Orchestrator On-Prem is affected by an OS command injection vulnerability. A remote attacker could exploit this to access privileged internal functionality, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data.
IFF Assessment
This vulnerability allows a remote attacker to access privileged functionality and impact the orchestrator, representing a significant threat to defenders.
Severity
The vulnerability is an OS command injection, allowing remote attackers to execute arbitrary commands. This has a high impact on confidentiality, integrity, and availability, with an easily exploitable attack vector.
CISA KEV: Listed as actively exploited. Federal patch due: July 30, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in Arista VeloCloud Orchestrator presents a critical risk, allowing remote attackers to gain privileged access and compromise sensitive data. Defenders should prioritize applying vendor-provided mitigations and ensure compliance with CISA directives for timely patching, especially considering potential impact on confidentiality, integrity, and availability.