Sceawere
Vulnerability Detail
CVE-2026-93952UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
VeloCloud Orchestrator Privilege Escalation Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 2h ago
- Vendor
- Arista Networks
- Product
- VeloCloud Orchestrator (VCO) On-Prem
- Attack Type
- CWE-20 Improper Input Validation
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-09-22T08:16:43.047Z",
"pubdate": "2026-09-22T08:16:43.047Z",
"executiveSummary": "A critical security vulnerability exists within the VeloCloud Orchestrator (VCO) platform, affecting both on-premises deployments and managed environments, including Hosted and Dedicated versions.\nThis vulnerability involves an improper access control or authentication bypass mechanism that permits a remote, unauthenticated or unauthorized attacker to gain access to privileged internal functionality.\nThe exploitation of this flaw poses a severe risk to the confidentiality, integrity, and availability of the orchestrator, as well as the sensitivity of the data managed within the infrastructure.\nBy bypassing standard security gates, an attacker can influence the orchestration logic, potentially leading to a complete compromise of the VCO host system.\nThe risk implication is significant due to the centralized nature of the orchestrator in managing network assets, where successful exploitation grants the adversary elevated privileges to execute unauthorized management tasks.\nImpacted parties include administrators of on-premises VCO instances and users of the VeloCloud hosted service; while cloud-hosted instances have received patches, on-premises administrators must ensure their deployments are updated to the latest security baseline to mitigate risk.",
"technicalDetails": "The vulnerability originates from a deficiency in the authorization enforcement logic within the VeloCloud Orchestrator (VCO) application interface. The root cause is likely an insecure handling of API requests or administrative functional calls that lack strict verification of the caller's privilege context.\nThe attack flow begins with the reconnaissance of the VCO management interface to identify endpoints that facilitate administrative or backend management tasks. An attacker leverages these endpoints to submit specifically crafted requests that bypass the standard authentication or authorization filters.\nBy manipulating these internal function calls, the attacker can interact with privileged components of the orchestrator host that are typically restricted to authenticated administrative users. This effectively grants the attacker the capability to execute commands or manipulate data flows that the orchestrator is entrusted to manage.\nSince the VCO acts as the central management plane for network components, the post-exploitation impact includes full control over the orchestrator's environment. This allows for the modification of network configurations, interception of managed data streams, or the total disabling of security and connectivity services.\nThe exploitation does not necessarily require local network access, as the orchestrator interface is often exposed to the network to facilitate management tasks. The vulnerability allows for remote interaction with the host, where the malicious payload is delivered via the application protocol used by the VCO, effectively tricking the service into executing the attacker's logic as a privileged user.\nThe absence of robust validation during the invocation of these internal functions allows an attacker to achieve lateral movement within the management plane. By compromising the VCO, the adversary gains the ability to leverage existing trust relationships between the orchestrator and the network appliances it governs.\nThis behavior results in a complete loss of the security integrity of the orchestrator, permitting the unauthorized modification of system files, credential exposure, or the persistent installation of malicious binaries if the host system's underlying OS is compromised through the orchestrator's interface."
}