## Overview
Arista Networks disclosed a critical vulnerability in the VeloCloud Orchestrator (VCO) on-premises version. The CVE-2026-16812 has a CVSS score of 10.0, indicating its severity. This vulnerability enables remote attackers to access internal functionality that should remain restricted.
## Technical Details
The vulnerability stems from improper access controls, allowing external entities to exploit internal features of the VCO. These features were designed for internal use only and were not meant to be accessible remotely. Successful exploitation could lead to unauthorized access to sensitive data and control over the orchestrator itself.
## Impact
The impact of this vulnerability is significant. Attackers could compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. With the potential for active exploitation already confirmed, organizations using the affected version of VCO face serious risks.
## Mitigation
Defenders should prioritize patching their systems. Arista Networks has already released patches for both the hosted and dedicated versions of VCO. Organizations running the on-prem version must apply these patches immediately to secure their environments against potential exploitation.
CSURFACE Threat Sensor