## Overview
Arista Networks disclosed a critical vulnerability in the VeloCloud Orchestrator (VCO) On-Prem. This issue, identified as CVE-2026-93952, has a CVSS score of 9.5, indicating its severity. The vulnerability allows remote attackers to access privileged internal functionality, potentially compromising the host and the data managed by the orchestrator.
## Technical Details
The vulnerability affects both hosted and dedicated versions of the VCO. Attackers exploiting this flaw can gain unauthorized access to sensitive functionalities. This could lead to unauthorized data manipulation and system control. The exact technical details of the exploit have not been publicly disclosed, but the implications are severe, affecting the confidentiality, integrity, and availability of the orchestrator's services.
## Impact
Successful exploitation of CVE-2026-93952 can lead to significant risks for organizations using VCO. Attackers could manipulate orchestrator settings, access sensitive data, and disrupt services. This could have cascading effects on network operations and data management, making immediate action critical for affected users.
## Mitigation
Arista Networks has already released patches for the hosted and dedicated versions of VCO. Organizations using these versions should apply the patches without delay to mitigate the risk. Additionally, it is advisable to review access controls and monitor for any unusual activity that may indicate exploitation attempts. Regularly updating systems and maintaining security best practices will further enhance defenses against such vulnerabilities.
CSURFACE Threat Sensor