CVE-2026-17192 Details
Description
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
A server-side request forgery (SSRF) vulnerability has been identified in Arista VeloCloud Orchestrator (VCO) versions 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, and 6.4.x prior to 6.4.2.4. This vulnerability arises from insufficient validation of caller-supplied input, allowing authenticated users with a minimum role of Enterprise Standard Admin to send requests on behalf of tenant accounts to internal services that are not normally accessible. The issue was discovered internally by Arista, which is not aware of any malicious exploitation in customer networks.
Users are advised to upgrade to VCO versions 5.2.3.14 or later, 6.1.3.4 or later, or 6.4.2.4 or later. For VCOs not on a supported release train, customers can contact Arista's Technical Assistance Center (TAC) to discuss possible upgrade options. Until the upgrade is applied, it is recommended to restrict access to the VCO web interface to trusted administrative networks, monitor for accesses from known malicious source IPs, watch for unexpected outbound network activity from the VCO host, and review recent administrator activity for any unexpected changes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.arista.com/en/support/advisories-notices/security-advisory/24365-security-advisory-0145 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | [email protected] |