External risk intelligence

VeloCloud Orchestrator Remote Privileged Access Vulnerability.

CVE advisoryKnown Exploit

CVE-2026-93952

The VeloCloud Orchestrator is a central management appliance designed to manage distributed network infrastructure. By design, these orchestrators often operate as edge-facing portals or gateways to facilitate communication with remote branches and network devices, making them highly likely to be internet-exposed in typical deployments.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in on-premises VeloCloud Orchestrator software, which could allow unauthorized remote access to critical internal functions, potentially impacting the orchestrator's host and the data it manages. Hosted versions have been patched, but on-premises deployments require attention to confirm their exposure and implement necessary actions.

  • Unauthorized remote access to core functions.
  • Affects on-premises network management software.
  • Confirm relevance and exposure for on-premises systems.

Attack Path

How an attacker could exploit the issue

An attacker can reach a vulnerable VeloCloud Orchestrator over the network without needing any prior access. The attacker would interact with a specific, but unspecified, feature of the orchestrator to trigger the vulnerability. If successful, this could allow them to access privileged functions and affect the orchestrator itself and the data it manages.

  • Entry condition: Network access required.
  • Trigger point: Interaction with a specific feature.
  • Resulting risk: Compromise of orchestrator and data.

Live Threat

Current exploitation, exposure, and threat context

A remote attacker could potentially access privileged functionality and impact the VeloCloud Orchestrator (VCO) host. This could lead to compromised confidentiality, integrity, and availability of the orchestrator and its managed data when supported by the advisory's conditions.

  • Orchestrator and managed data at risk.
  • Remote access to privileged functionality.
  • Compromise of confidentiality, integrity, availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Arista VeloCloud Orchestrator (VCO) on-prem deployments are the primary concern, as hosted versions have already been patched. Infrastructure and security teams should first identify all VCO instances, determine their exposure and criticality, and locate the accountable owner for remediation planning.

  • Infrastructure and security teams own this.
  • Verify all on-prem VCO instances.
  • Plan remediation based on risk exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the VeloCloud Orchestrator?

VeloCloud Orchestrator (VCO) is a centralized management platform provided by Arista. It serves as the control center for software-defined wide area network (SD-WAN) infrastructure, allowing administrators to configure, monitor, and manage distributed network appliances and branch office connectivity from a unified interface.

What does CVE-2026-93952 mean for the software?

This vulnerability is classified as improper input validation (CWE-20). In plain terms, the orchestrator does not correctly verify data sent to it by users. Because this process is flawed, a remote attacker can bypass normal security checks to interact with privileged internal functions that should be off-limits to unauthorized parties.

How is this vulnerability triggered?

An attacker triggers the flaw by sending specifically crafted network traffic to interact with a particular feature within the orchestrator. Simply having network access is the primary precondition; the system does not require the attacker to have an existing account or prior credentials to initiate the interaction.

Why should I care about my VeloCloud Orchestrator instance?

Halo Surface Signal indicates that VCO appliances are frequently deployed as internet-facing gateways to support remote branch communication. If your instance is reachable from the public internet, it falls into the high-risk category for this vulnerability because attackers can reach the management interface remotely.

What should I do if I run on-premises VCO?

Your first step is to create a complete inventory of all on-premises VCO instances. Once identified, evaluate their network exposure, consult the official security advisory from Arista, and prioritize the application of vendor-provided patches or mitigations to secure the management host and the sensitive network data it oversees.

References