This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Project Subscriptions
No data.
No advisories yet.
Solution
The recommended resolution is to upgrade to a fixed VCO release at your earliest convenience. These vulnerabilities have been fixed in the following releases: * VCO 5.2.3.14 and later in the 5.2 train * VCO 6.1.3.4 and later in the 6.1 train * VCO 6.4.2.4 and later in the 6.4 train
Workaround
Until the fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment: * Restrict access to the VCO web interface to trusted administrative networks. * Monitor the VCO for accesses from known malicious source IPs. * Monitor for unexpected outbound network activity from the VCO host. * Review recent administrator activity for unexpected changes.
Mon, 27 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. | |
| Title | VeloCloud Orchestrator Flow Metrics API SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-07-27T17:29:45.538Z
Reserved: 2026-07-24T19:03:13.728Z
Link: CVE-2026-17191
No data.
No data.
No data.
OpenCVE Enrichment
No data.