← Back to search

CVE-2026-93952

10 CRITICAL

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
The VeloCloud Orchestrator (VCO) on-premises version has a critical vulnerability that allows remote attackers to access privileged internal functionality, compromising the confidentiality, integrity, and availability of the orchestrator and its managed data.
Exploitability
Exploitation is relatively straightforward given the remote access vector and lack of user interaction required. The attacker needs network access to the VCO on-premises version.
Blast radius
If exploited, the impact is severe, as it can compromise the entire orchestrator and the data it manages, affecting multiple systems and services.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of VCO on-premises, specifically version 2.590 or later, as published by the vendor.
rcepriv-escalationorchestratoron-premcritical

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-20

Vendors

arista

Products

velocloud orchestrator

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.