Security experts have highlighted a significant command injection vulnerability in VeloCloud Orchestrator (VCO) systems that is currently being exploited in the wild. This flaw, identified as CVE-2026-16812, permits remote attackers to execute privileged commands, potentially gaining control over the VeloCloud Orchestrator host.
Understanding the Vulnerability
Rated with a maximum severity score of 10.0 on both CVSS v3.1 and v4.0 scales, the vulnerability is linked to CWE-78, which pertains to insufficient neutralization of special elements in operating system commands. Such weaknesses can allow malicious input to be processed as system commands, posing a severe risk.
VeloCloud Orchestrator is integral for managing SD-WAN infrastructures, encompassing connected Edge devices, network configurations, and sensitive data. A successful exploit could undermine the confidentiality, integrity, and availability of the orchestrator and its managed data.
Scope and Impact
The vulnerability affects specific on-premises deployments of VCO, where attackers need only network access to the default-exposed web interface. No VCO tenant or operator credentials are required for exploitation.
Affected versions include VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Companies should verify the precise version in use, as other products like VeloCloud Gateway and Edge, and certain Arista products, remain unaffected.
Mitigation and Recommendations
Organizations are urged to upgrade immediately to secure versions—5.2.3.14 and beyond for VCO 5.2.x, 6.1.3.4 and beyond for 6.1.x, and 6.4.2.4 and beyond for 6.4.x. Enterprises using unsupported versions should consult Arista Technical Assistance for guidance.
Until updates are applied, it’s crucial to limit VCO web interface access to trusted networks and actively monitor for suspicious activities. Indicators such as unusual web requests, unexpected outbound traffic, and configuration anomalies should prompt investigation.
Proactive Security Measures
Administrators are advised to review logs for any irregularities, such as anomalous URL components or high-volume requests. Blocking identified malicious IP addresses—8.19.75.217, 206.72.242.124, and 206.72.242.162—is recommended.
If a system compromise is suspected, logs should be preserved before remediation. Since an orchestrator breach could affect managed Edge devices, it’s important to rotate credentials, verify device states, and ensure restoration from trusted sources.
Enhance your security operations by integrating rapid threat detection solutions to strengthen your infrastructure against such vulnerabilities.
