---
id: CVE-2026-86109
title: >-
  The VeloCloud Edge software update workflow may accept update bundles without
  properly validating their signatures because the workflow does not restrict
  the digest algorithm used for artifact verification
summary: >-
  The VeloCloud Edge software update workflow may accept update bundles without
  properly validating their signatures because the workflow does not restrict
  the digest algorithm used for artifact verification. An attacker with either
  suffic…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-347
vendor: Arista Networks
product: VeloCloud Edge
affected:
  - velocloud_edge >= 6.4.0 <= 6.4.1.x
  - velocloud_edge >= 6.1.0 <= 6.1.4.x
  - velocloud_edge >= 5.2.0 <= 5.2.6.x
  - velocloud_edge >= 0.0.0 < 5.2.0
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:17:12.480'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86109'
references:
  - url: >-
      https://www.arista.com/zh/support/advisories-notices/security-advisory/24738-security-advisory-0182
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T17:40:03.578525Z'
epss: 0.00243
epssPercentile: 0.13711
ingestedAt: '2026-09-16T03:49:03.876Z'
---

## Overview

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
