---
id: CVE-2026-86106
title: >-
  An unauthenticated actor with network access to the private HA interconnect
  may trigger sensitive HA peer functions without verification
summary: >-
  An unauthenticated actor with network access to the private HA interconnect
  may trigger sensitive HA peer functions without verification. This could
  result in elevated command execution on Edge units where HA is enabled.
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: Arista Networks
product: VeloCloud Edge
affected:
  - velocloud_edge >= 1.0.0.0 < 5.2.0.0
  - velocloud_edge >= 5.2.0.0 < 5.2.7.0
  - velocloud_edge >= 6.1.0.0 < 6.1.5.0
  - velocloud_edge >= 6.4.0.0 < 6.4.2.0
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:36:52.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86106'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24735-security-advisory-0179
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-16T17:52:49.256029Z'
ingestedAt: '2026-09-16T10:53:54.010Z'
epss: 0.00356
epssPercentile: 0.26567
---

## Overview

An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
