[CIVN-2026-0384] Command Injection Vulnerability in Arista

By Published On: July 31, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Command Injection Vulnerability in Arista


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Arista VeloCloud Orchestrator (VCO) On-Prem 5.2.x releases prior to 5.2.3.14

Arista VeloCloud Orchestrator (VCO) On-Prem 6.1.x releases prior to 6.1.3.4

Arista VeloCloud Orchestrator (VCO) On-Prem 6.4.x releases prior to 6.4.2.4

Arista VeloCloud Orchestrator (VCO) On-Prem 7.0.x releases prior to 7.0.0.1

Overview


A vulnerability has been reported in Arista VeloCloud Orchestrator (VCO) On-Prem which could allow a remote, unauthenticated attacker to execute arbitrary commands, leading to unauthorized access and complete compromise of the targeted system.


Target Audience:

All organizations and individuals using affected versions of Arista products.


Risk Assessment:

Critical risk of remote code execution, unauthorized access and complete system compromise.


Impact Assessment:

Potential for complete compromise of the affected system, unauthorized access, and loss of confidentiality, integrity and availability.


Description


Arista VeloCloud Orchestrator (VCO) On-Prem is a centralized management platform used to configure, monitor and manage VeloCloud SD-WAN deployments.


A command injection vulnerability has been reported in Arista VCO On-Prem due to improper neutralization of special elements used in an operating system command. The vulnerability exposes privileged internal functionality intended only for internal use, which is remotely accessible through the VCO web interface. A remote attacker could exploit this vulnerability by sending crafted requests.


Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary commands, leading to unauthorized access and complete compromise of the targeted system.


Solution


Apply appropriate updates as mentioned as mentioned by the Vendor:

https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144



Vendor Information


Arista Networks

https://www.arista.com/en/support/advisories-notices


References


 

https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144


CVE Name

CVE-2026-16812




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpssTUACgkQ3jCgcSdc

ys9lVw/+LQ1MqB2zFA96xJr6S+09pF8Y8OO3QuFtnltlrSHESmkNRc/XXbsDiaI5

VB0jcdDCSUxSPxYVYngLTYCiWBEaChx05C+IGiv2pBr3o4Q2MWnNWCnPDxj8rtND

PYdLTSqAV3DSSwyYQD2bIrzUs4IbLWqRmuFc8MrFi8swUmTNBm61W7Iz6twKfpxh

3cpsPMtxwOc0P04oYLr6ALCLCyHQxmphVN5uaBFocHIJtkw4fpC9M1IVUGFDYsgQ

Zo/25e5Cvh5LmvbnT8TVRY2q+gYnT8mZe0zpDKQ7V3lrzdbY0pFH3ZpurT/3vZyG

khc+9s3nbcBzswv59WFD7NdtAuxAR4Zr7O3DruDsWxYkJGulNIH73gtle9AcUheI

o0KjiSIEHjuXjpHZwyjYosBEdk5v5EhI0MOqdWVqh3e6AVBgtPNdBRfjZiZT3z5A

DDZU8uNWSiePrhA59F/b4gudi8uR6CjpT/CxVKqUf2mbGprDbJrg6nYLMKe4OaiS

/yFCOmFBcQNqtnNpEQFpOdCTlH3hnbZm+AlwY7CG9QGwvFgCwscsUFJXK/H1AvDD

igCpbzzXcq4fwgXnV94YXIJN64eYdIfVfgOB0hucClJ68zWdVk9PeO9GVtxWWjyo

3rE0MVAwV0zXjWEW1zTriaxR1Rtid0bKFy9Ao0MpKCMx4lV2/KE=

=1ARR

—–END PGP SIGNATURE—–

Share this article