Who is affected
This vulnerability affects Arista VeloCloud Orchestrator (VCO) deployed on-premises. The flaw is an improper input validation issue that can permit remote, unauthenticated access to privileged functions within the orchestrator application and the underlying host system. The record does not specify which versions of VCO are vulnerable, nor does it indicate whether the cloud-hosted variant is affected.
How to check whether this touches you
- Search your asset inventory for any instance of "VeloCloud Orchestrator" or "VCO" labelled as on-premises or self-hosted deployment.
- Confirm whether each VCO instance is reachable over the network from outside your organisation (via network segmentation maps, firewall rules, or direct probing of management interfaces).
- Obtain the running software version from the VCO admin console or API; consult Arista's advisory to determine which versions contain the flaw, as version ranges are not specified in this record.
- If you cannot establish the exact version, treat the instance as potentially vulnerable unless Arista explicitly confirms otherwise in their guidance.
What to do
- Immediately: Locate Arista's official security advisory for CVE-2026-93952 and confirm the affected version range and available remediation (patch, configuration change, or workaround).
- In parallel: Isolate each affected VCO instance from external network access by restricting inbound routes to trusted administrative clients only, via firewall or network segmentation.
- Before patching: Log all access to the VCO management interface, including failed authentication attempts and any API calls, for the period before you discovered and remediated this issue.
- Escalate immediately: If your VCO instance is internet-facing, has no patch available, or cannot be isolated, escalate to senior infrastructure and security leadership to evaluate whether discontinuation of the service is necessary under CISA BOD 26-04 guidance.
- Apply remediation: Follow Arista's patching instructions and verify successful application in a test environment before rolling out to production.
If you find you were exposed
Check your access logs and network telemetry for the period from when this vulnerability was introduced (unknown from this record) back as far as your log retention allows. Look for any unauthenticated connections to the VCO management port, unusual API calls, or privilege escalation attempts originating from outside your network. If exploitation did occur, you must assume that the confidentiality, integrity and availability of the orchestrator itself and any data it manages may be compromised, and engage incident response and forensics accordingly.