πŸ”΄ CVE-2026-93952

CVE-2026-93952 is a CVSS 10.0 critical authentication bypass vulnerability in Arista Networks VeloCloud Orchestrator (VCO) On-Prem arising from improper input validation (CWE-20). A remote, unauthenticated attacker who can reach the VCO web interface can access privileged internal functionality and fully compromise the orchestrator host β€” impacting confidentiality, integrity, and availability. Active exploitation in the wild has been reported, with CISA SSVC rating the vulnerability as automatable with total technical impact.

← Back to Overview
HIGH_RISK
Risk Level
10.0
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 β€” Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-22

Added to CISA KEV: 2026-09-22 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2026-09-22)

Summary

CVE-2026-93952 is a critical security vulnerability (CVSS 10.0) affecting on-premises installations of the VeloCloud Orchestrator (VCO) component. The flaw stems from a failure in access control mechanisms, which allows a remote, unauthenticated attacker to access privileged internal functionality within the Orchestrator. This vulnerability is highly significant because it can lead to a complete compromise of the orchestrator host and the sensitive data managed by the system, necessitating immediate attention from organizations utilizing on-premises VCO deployments.

Exploitation

  • Active Exploitation: The vulnerability is currently being exploited in the wild, with attackers specifically targeting certificate-authenticated VeloCloud Orchestrators [1].
  • Threat Actors: Reports indicate active exploitation campaigns are underway, though specific named threat actors or ransomware groups have not been broadly publicized at this time [1].
  • Proof-of-Concept: While exploit activity is confirmed in the wild, public proof-of-concept code is generally managed within security advisories or limited researcher disclosures to minimize further risk.
  • Attack Prerequisites: The attack is remote and does not require user interaction or valid login credentials; however, it requires the attacker to be able to reach the VCO service over the network [4][5].

Affected Products & Patches

  • Affected Products: On-premises versions of the VeloCloud Orchestrator (VCO) are impacted. While hosted and dedicated versions were also affected, those environments have reportedly been remediated [2].
  • Patch Availability: Organizations should review the official Arista Networks security advisory (Security Advisory 0183) for the specific release train patches or hotfixes required for their deployment [3].
  • Mitigation: Where patches cannot be applied immediately, access to the VCO service should be restricted at the network level to prevent unauthorized remote access until updates are installed.

Impact

  • System Access: Successful exploitation provides a remote attacker with access to privileged internal functions of the VeloCloud Orchestrator, allowing them to impact the VCO host directly.
  • Business Risk: The risk to internet-facing deployments is critical, as it can result in the full compromise of the confidentiality, integrity, and availability of the orchestrator itself and all associated network data managed by the system [2][3].

Sources

  1. New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in ...

    Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes.

  2. CVE-2026-93952 - Vulnerability Details - OpenCVE

    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by…

  3. Security Advisory 0183 - Arista

    September 22, 2026 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality,…

  4. CVE-2026-93952 - Exploits & Severity - Feedly

    A critical vulnerability CVE-2026-93952 in the VeloCloud Orchestrator VCO is being actively exploited, allowing remote attackers to access privileged internal functions without needing login credentia…

  5. CVE-2026-93952 in VeloCloud Orchestrator On-Prem

    The presence of this issue indicates a failure in proper access control mechanisms, allowing an attacker who can reach the VCO service over the ...