CVE-2026-17191 Details
Description
An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
A SQL injection vulnerability has been identified in the VeloCloud Orchestrator (VCO) API, specifically within the flow metrics API method. This vulnerability allows authenticated users to manipulate backend SQL queries, potentially leading to unauthorized access to data beyond their privileges. Additionally, it can cause the system to make unintended outbound network connections. The vulnerability affects VCO versions 5.2.x prior to 5.2.3.14, 6.1.x releases prior to 6.1.3.4, and 6.4.x releases prior to 6.4.2.4. The issue requires a valid authenticated session on the VCO portal, with a minimum user role of Enterprise Read Only.
Users are advised to upgrade to VCO versions 5.2.3.14, 6.1.3.4, or 6.4.2.4. For VCOs not on a supported release train, customers can contact the Arista Technical Assistance Center (TAC) to discuss upgrade options. Until the upgrade is applied, it is recommended to restrict access to the VCO web interface to trusted administrative networks, monitor for unexpected outbound network activity, and review recent administrator activity for any unexpected changes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.arista.com/en/support/advisories-notices/security-advisory/24365-security-advisory-0145 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | [email protected] |