PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17192 Arista Networks CVE debrief

CVE-2026-17192 is a medium-severity vulnerability in an Arista product's VCO feature. The issue allows requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. Arista discovered the issue internally and is not aware of any malicious uses in customer networks. The vulnerability has a CVSS score of 6.3 and a CVSS severity of MEDIUM.

Vendor
Arista Networks
Product
VeloCloud Orchestrator On-Prem
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Administrators and users of Arista products, particularly those with the Enterprise Standard Admin role, should be aware of this vulnerability and take necessary precautions. This includes reviewing and updating access controls for the VCO feature, monitoring for suspicious activity, and applying vendor patches or workarounds when available. The vulnerability's impact on the organization should be assessed, and mitigation strategies should be developed.

Technical summary

The VCO feature does not sufficiently validate caller-supplied input, allowing unauthorized requests to internal services. This requires a minimum role of Enterprise Standard Admin. The vulnerability has a CVSS score of 6.3 and a CVSS severity of MEDIUM. Arista discovered the issue internally and is not aware of any malicious uses in customer networks. The CVE record and NVD details provide additional context for defenders to assess the vulnerability's impact and develop mitigation strategies.

Defensive priority

Medium priority due to the requirement for a specific role and the potential for unauthorized access to internal services. Administrators should review and update access controls for the VCO feature, monitor for suspicious activity, and apply vendor patches or workarounds when available. The CVE record and NVD details provide additional context for defenders to assess the vulnerability's impact and develop mitigation strategies. Defenders should verify the affected product deployments in managed environments and assign an owner for follow-up. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Exceptions, retest remediated assets, and close the item only after evidence is documented. Tracking changes and source grounding can help defenders stay informed about the vulnerability's scope and impact. The Arista security advisory for CVE-2026-17192 provides additional information for defenders to assess the vulnerability's impact and develop mitigation strategies. The official CVE record and NVD details provide additional context for defenders to assess the vulnerability's impact and develop mitigation strategies. The vulnerability's CVSS score and severity can help defenders prioritize their mitigation efforts. The minimum role required to exploit the vulnerability can help defenders identify potential targets and develop targeted mitigation strategies. The fact that Arista discovered the issue internally and is not aware of any malicious uses in customer networks can help defenders assess the vulnerability's likelihood of exploitation. The CVE record's publication date and modification history can help defenders track changes and updates to the vulnerability's information. The Arista security advisory's publication date and modification history can help defenders track changes and updates to the vulnerability's information. The NVD details' publication date and modification history can help defenders track changes and updates to the vulnerability's information. The CVE record's CVSS score and severity can help who

Recommended defensive actions

  • Review and update access controls for the VCO feature
  • Monitor for suspicious activity
  • Apply vendor patches or workarounds when available
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Evidence is limited to the CVE record and NVD details. Further investigation is recommended to determine the full scope of the vulnerability. The CVE record was published on 2026-07-27T17:16:35.573Z and has not been modified since then. The vulnerability requires a minimum role of Enterprise Standard Admin. Arista discovered the issue internally and is not aware of any malicious uses in customer networks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-17192 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-17192

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-17192 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17192

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.arista.com/en/support/advisories-notices/security-advisory/24365-security-advisory-0145

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.