First published · Last updated
CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
An improper input validation flaw in Arista VeloCloud Orchestrator on-prem may allow remote attackers to access privileged internal functionality and impact the VCO host. The advisory instructs applying vendor mitigations and following CISA’s BOD 26-04 and forensics triage guidance.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 4/10
- Global importance
- 4/10
- Impact magnitude
- 5/10
- Positivity
- 2/10
- Urgency
- 7/10
Why it matters
Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data it manages.

