Knox CVE Database
/
CVE-2026-93952
Critical
9.5

CVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Added to the CISA KEV catalog:
September 22, 2026

Overview

Arista VeloCloud Orchestrator (VCO) on-premises deployments contain an improper input validation flaw that allows a remote attacker to reach privileged internal functionality without authorization. Successful exploitation can fully compromise the orchestrator, affecting the confidentiality, integrity, and availability of both the VCO host and all network data it manages. Versions through 5.2.3.15, 6.1.3.7, 6.4.2.7, and 7.0.0.2 are affected; hosted and dedicated VCO instances were patched separately by Arista.

Vulnerability details

Affected vendor
Arista
Affected product
VeloCloud Orchestrator
Weakness type (CWE)
CWE-20

Improper input validation (CWE-20) occurs when an application fails to enforce adequate checks on attacker-supplied data before passing it to internal processing logic. In VeloCloud Orchestrator, the flaw exists on a network-accessible interface where the orchestrator does not sufficiently validate incoming requests. This allows crafted input to bypass the validation boundary and reach internal functionality that should be restricted to privileged operations. Because the orchestrator manages SD-WAN edge devices and the policies governing them, the attack surface is significant: any network-reachable instance is potentially exposed.


An attacker sends crafted requests to the VCO's network-accessible interface. The CVSS vector rates the attack as requiring no privileges, although the advisory does not explicitly confirm unauthenticated access, and the attack carries some complexity, suggesting specific input construction is required to bypass validation gates. If successful, the attacker gains access to privileged internal functionality of the VCO host, with potential full impact on confidentiality, integrity, and availability of the orchestrator and all data it manages. The precondition is an on-premises deployment reachable from the attacker's network position; hosted and dedicated instances were already remediated by Arista before public disclosure.

Severity and impact

9.5
Critical
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review VCO application and web server logs for requests to internal or administrative API endpoints originating from sources outside expected management networks, particularly those with malformed or anomalous parameter structures.
  • Monitor for unexpected privilege escalation events or access to administrative functions in VCO audit logs where no corresponding authenticated management session exists, which may indicate validation bypass.
  • Audit network perimeter controls to confirm whether the VCO management interface is exposed to untrusted networks; internet-facing on-premises deployments with no access restriction represent the highest-risk posture for this flaw.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 25, 2026

Additional hardening

  • Upgrade on-premises VCO to version 5.2.3.16 or later for the 5.2 release line, and to 6.4.2.8 or later for the 6.4 release line; consult the vendor advisory listed in References for fixed boundaries across the 6.1 and 7.0 release lines.
  • Restrict network access to the VCO management interface using firewall rules or access control lists so only known, trusted management hosts and IP ranges can reach it, reducing exposure to unauthenticated remote attackers.
  • Place the VCO management plane on a dedicated, segmented management network isolated from general user traffic and internet-facing interfaces, limiting the attacker population that can send crafted requests.
  • Conduct forensic triage of VCO audit logs and host-level indicators per CISA BOD 26-04 forensics triage requirements, referenced in the References section, to identify any prior exploitation attempts before patching.

Key dates

Published (NVD)
September 22, 2026
Added to CISA KEV
September 22, 2026
Remediation deadline
September 25, 2026
Last updated
September 23, 2026

References

Frequently asked questions

Does CVE-2026-93952 affect my FedRAMP authorization?

If Arista VeloCloud Orchestrator runs inside your authorization boundary, yes. CVE-2026-93952 appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of September 25, 2026 has already passed. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding. An overdue one is a finding your assessor and sponsoring agency can see right now. You either remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-93952?

Knox does not patch your software. Remediating Arista VeloCloud Orchestrator is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage that support documentation of the fix for your next assessment. The remediation work is yours to carry out; maintaining a defensible compliance posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-93952 surfaces, exposure appears during ongoing monitoring rather than waiting until an assessor flags it at review time. That gap between disclosure and discovery is where risk lives, and continuous monitoring closes it.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-93952's remediation deadline of September 25, 2026 has passed. What happens now?

An unremediated CVE-2026-93952 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out now and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid ground.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.