{"id":"CVE-2026-93952","published":"2026-09-22T08:16:43.047","lastModified":"2026-09-23T14:32:12.417","description":"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.\n\nHosted, including Dedicated, versions of VCO were impacted and have already been patched.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-20"],"vendors":["arista"],"products":["velocloud orchestrator"],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183","tags":["Mitigation","Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952","tags":["US Government Resource"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The VeloCloud Orchestrator (VCO) on-premises version has a critical vulnerability that allows remote attackers to access privileged internal functionality, compromising the confidentiality, integrity, and availability of the orchestrator and its managed data.","exploitability":"Exploitation is relatively straightforward given the remote access vector and lack of user interaction required. The attacker needs network access to the VCO on-premises version.","blast_radius":"If exploited, the impact is severe, as it can compromise the entire orchestrator and the data it manages, affecting multiple systems and services.","remediation":"Upgrade to the latest version of VCO on-premises, specifically version 2.590 or later, as published by the vendor.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","priv-escalation","orchestrator","on-prem","critical"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:54:11.788Z"}}