CVE-2026-93952 is a CVSS 10.0 critical authentication bypass vulnerability in Arista Networks VeloCloud Orchestrator (VCO) On-Prem arising from improper input validation (CWE-20). A remote, unauthenticated attacker who can reach the VCO web interface can access privileged internal functionality and fully compromise the orchestrator host β impacting confidentiality, integrity, and availability. Active exploitation in the wild has been reported, with CISA SSVC rating the vulnerability as automatable with total technical impact.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-22
Added to CISA KEV: 2026-09-22 0 DAY BETWEEN CVE AND KEV
CVE-2026-93952 is a critical security vulnerability (CVSS 10.0) affecting on-premises installations of the VeloCloud Orchestrator (VCO) component. The flaw stems from a failure in access control mechanisms, which allows a remote, unauthenticated attacker to access privileged internal functionality within the Orchestrator. This vulnerability is highly significant because it can lead to a complete compromise of the orchestrator host and the sensitive data managed by the system, necessitating immediate attention from organizations utilizing on-premises VCO deployments.
Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes.
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed byβ¦
September 22, 2026 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality,β¦
A critical vulnerability CVE-2026-93952 in the VeloCloud Orchestrator VCO is being actively exploited, allowing remote attackers to access privileged internal functions without needing login credentiaβ¦
The presence of this issue indicates a failure in proper access control mechanisms, allowing an attacker who can reach the VCO service over the ...