VeloCloud Orchestrator Vulnerability Exposes Critical Flaw, Urgent Patching Required
A newly identified vulnerability within the VeloCloud Orchestrator poses significant risks for organizations relying on this platform to manage their VeloCloud SD-WAN subscriptions. The acquired flaw allows unauthorized remote access, threatening internal functionality and potentially impacting edge devices. This is more significant than it looks — with many organizations increasingly depending on SD-WAN for their networking needs, the implications of such vulnerabilities can be far-reaching.
Impacts of the Vulnerability
The vulnerabilities associated with VeloCloud could lead to severe operational disruptions and data breaches, particularly for those handling sensitive data. Organizations utilizing VeloCloud’s orchestration capabilities are now tasked with assessing the risk that this flaw introduces. Unchecked, this vulnerability could enable attackers to launch attacks that compromise entire networks and gather sensitive information.
Arista, the current owner of the VeloCloud business, has issued warnings to its clients regarding vulnerable configurations prevalent in on-premises deployments of the VeloCloud Orchestrator. While patches have been rolled out for Hosted and Dedicated VCO deployments, the on-premises versions require immediate user action. The oversight in patch rollout has raised concerns among clients, potentially leaving many organizations exposed during an increasingly challenging security environment. According to Arista, the flaw, which has been publicly disclosed, has been confirmed to be actively exploited in the wild, which raises the stakes further for impacted organizations.
“This issue was recognized externally and poses a real danger,” Arista stated in its advisory. Organizations are urged to upgrade to the patched versions of the VCO to mitigate risks. However, fixes are not yet available for all impacted versions, leaving many clients in a precarious situation. The lack of a complete patch strategy can be seen as a critical lapse, indicating the need for timely updates and constant vigilance in software security.”
Spotlight on the Flaw: Technical Details
This vulnerability is classified under CVE-2026-93952 and is primarily characterized by improper input validation, boasting a critical CVSS score of 10.0. This high score signifies that potential damage from exploitation could be severe, a reality not lost on security teams. However, the exploitation of this flaw is contingent upon specific conditions: a VCO deployment needs to enable certificate-based authentication from the VeloCloud Edge to the VeloCloud Orchestrator, and the attacker must have both the public key of the Edge authentication certificate and network access to the VCO web interface. Notably, permanent credentials for VCO tenants or operators aren't required for these attacks, simplifying the exploit process for potentially malicious actors.
Security experts, including Andrew Costis from AttackIQ, have pointed out that this flaw strongly resembles a cross-site request forgery (CSRF) vulnerability. This allows malicious actors to exploit an Edge certificate, bypassing front-end security measures and accessing internal services—a process that many organizations may underestimate. Here’s the thing: even organizations with a strong security posture can find themselves vulnerable if they overlook the implications of such circumvention techniques.
Identifying Affected Versions
The affected versions include VCO releases across various trains—5.2.3.15 and earlier in the 5.2.x series, 6.1.3.7 and earlier in the 6.1.x, 6.4.2.7 and earlier in the 6.4.x, and 7.0.0.2 and earlier in the 7.0.x series. While patches for versions 5.2.3.16 and later (5.2.3 series) and 6.4.2.8 and later (6.4.2 series) have already been released, fixes for other releases are still pending. This delay may further exacerbate the security risks for clients still relying on outdated systems, leading to a pressing need for organizations to manage their upgrade timelines effectively.
Recommended Preventative Measures
For organizations unable to perform immediate upgrades, Arista recommends limiting access to the VCO web interface strictly to trusted administrative networks. Since the vulnerability allows attackers to exploit weaknesses remotely, restricting access could serve as a vital stopgap measure. It's also advisable to monitor for unusual activities—such as connections from known malicious IP addresses, unexpected outbound traffic, and unauthorized admin changes. Such vigilance requires ongoing attention and operational discipline.
Arista warns that successful exploitation could compromise both the orchestrator and the data it manages, leading to potential breaches of sensitive information. The company provided several indicators of compromise, including suspicious files and HTTP headers associated with exploitation attempts. This guidance carves out a pathway for organizations to detect early signs of potential breaches, emphasizing the need to stay proactive rather than reactive.
Costis of AttackIQ reiterates the importance of proactive threat exposure management, asserting that understanding which orchestrators are accessible and ensuring access controls are enforced is vital to security integrity. This vulnerability marks the second critical flaw in VeloCloud's system that Arista has had to address this year, exemplifying the ongoing security challenges in the sector and prompting questions about system resilience and development practices.
This article first appeared on Network World.