---
id: CVE-2026-93952
title: >-
  VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may
  allow a remote attacker to access privileged internal functionality and impact
  the VCO host
summary: >-
  VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may
  allow a remote attacker to access privileged internal functionality and impact
  the VCO host. Successful exploitation may compromise the confidentiality,
  integ…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: arista
product: velocloud_orchestrator
affected:
  - 'velocloud_orchestrator >= 5.2.0, < 5.2.3.16'
  - 'velocloud_orchestrator >= 6.1.0, <= 6.1.3.7'
  - 'velocloud_orchestrator >= 6.4.0, < 6.4.2.8'
  - 'velocloud_orchestrator >= 7.0.0, <= 7.0.0.2'
patched:
  - velocloud_orchestrator 6.4.2.8
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T14:32:12.417'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93952'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
    label: psirt@arista.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - cve.org
  - exploit-available
epss: 0.00895
epssPercentile: 0.57763
kev: true
kevDateAdded: '2026-09-22'
kevDueDate: '2026-09-25'
kevRansomware: false
exploited: true
zeroDay: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-22T19:40:04.719145Z'
ingestedAt: '2026-09-22T08:00:27.697Z'
---

## Overview

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

## Affected

- `velocloud_orchestrator >= 5.2.0, < 5.2.3.16`
- `velocloud_orchestrator >= 6.1.0, <= 6.1.3.7`
- `velocloud_orchestrator >= 6.4.0, < 6.4.2.8`
- `velocloud_orchestrator >= 7.0.0, <= 7.0.0.2`

## Remediation

Upgrade past the affected range:

- `velocloud_orchestrator 6.4.2.8`
