{"api_version":"1","generated_at":"2026-07-27T20:48:31+00:00","cve":"CVE-2026-17191","urls":{"html":"https://cve.report/CVE-2026-17191","api":"https://cve.report/api/cve/CVE-2026-17191.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-17191","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-17191"},"summary":{"title":"VeloCloud Orchestrator Flow Metrics API SQL Injection","description":"An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections.\n\n\n\n\nThis issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.","state":"PUBLISHED","assigner":"Arista","published_at":"2026-07-27 17:16:35","updated_at":"2026-07-27 18:16:53"},"problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[{"version":"4.0","source":"psirt@arista.com","type":"Secondary","score":"8.5","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"PRESENT","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"8.5","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/S:P","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"PRESENT","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.5,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/S:P","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"}},{"version":"3.1","source":"psirt@arista.com","type":"Secondary","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24365-security-advisory-0145","name":"https://www.arista.com/en/support/advisories-notices/security-advisory/24365-security-advisory-0145","refsource":"psirt@arista.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-17191","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17191","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Arista Networks","product":"VeloCloud Orchestrator On-Prem","version":"affected 5.2.0 5.2.3.14 custom","platforms":[]},{"source":"CNA","vendor":"Arista Networks","product":"VeloCloud Orchestrator On-Prem","version":"affected 6.1.0 6.1.3.4 custom","platforms":[]},{"source":"CNA","vendor":"Arista Networks","product":"VeloCloud Orchestrator On-Prem","version":"affected 6.4.0 6.4.2.4 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The recommended resolution is to upgrade to a fixed VCO release at your earliest convenience.\n\n\n\n\nThese vulnerabilities have been fixed in the following releases:\n\n\n\n  *  VCO 5.2.3.14 and later in the 5.2 train\n\n  *  VCO 6.1.3.4 and later in the 6.1 train\n\n  *  VCO 6.4.2.4 and later in the 6.4 train","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"Until the fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment:\n\n\n\n  *  Restrict access to the VCO web interface to trusted administrative networks.\n\n  *  Monitor the VCO for accesses from known malicious source IPs.\n\n  *  Monitor for unexpected outbound network activity from the VCO host.\n\n  *  Review recent administrator activity for unexpected changes.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-17191","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-27T17:29:37.640962Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-27T17:29:45.538Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"VeloCloud Orchestrator On-Prem","vendor":"Arista Networks","versions":[{"lessThan":"5.2.3.14","status":"affected","version":"5.2.0","versionType":"custom"},{"lessThan":"6.1.3.4","status":"affected","version":"6.1.0","versionType":"custom"},{"lessThan":"6.4.2.4","status":"affected","version":"6.4.0","versionType":"custom"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>A successful attack requires a valid authenticated session on the VCO portal. The minimum user role required is <strong>Enterprise Read Only</strong>, the lowest built-in tenant role. No non-default configuration is required.</p>"}],"value":"A successful attack requires a valid authenticated session on the VCO portal. The minimum user role required is Enterprise Read Only, the lowest built-in tenant role. No non-default configuration is required."}],"datePublic":"2026-07-27T16:37:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections.</p>\n<p>This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.</p>"}],"value":"An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections.\n\n\n\n\nThis issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks."}],"impacts":[{"capecId":"CAPEC-66","descriptions":[{"lang":"en","value":"CAPEC-66: SQL Injection"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"PRESENT","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.5,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/S:P","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-27T16:41:17.436Z","orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista"},"references":[{"name":"Security Advisory 0145","tags":["vendor-advisory"],"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24365-security-advisory-0145"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The recommended resolution is to upgrade to a fixed VCO release at your earliest convenience.</p>\n<p>These vulnerabilities have been fixed in the following releases:</p>\n<ul>\n<li>VCO <strong>5.2.3.14</strong> and later in the 5.2 train</li>\n<li>VCO <strong>6.1.3.4</strong> and later in the 6.1 train</li>\n<li>VCO <strong>6.4.2.4</strong> and later in the 6.4 train</li>\n</ul>"}],"value":"The recommended resolution is to upgrade to a fixed VCO release at your earliest convenience.\n\n\n\n\nThese vulnerabilities have been fixed in the following releases:\n\n\n\n  *  VCO 5.2.3.14 and later in the 5.2 train\n\n  *  VCO 6.1.3.4 and later in the 6.1 train\n\n  *  VCO 6.4.2.4 and later in the 6.4 train"}],"source":{"advisory":"145","defect":["BUG 1568507"],"discovery":"INTERNAL"},"title":"VeloCloud Orchestrator Flow Metrics API SQL Injection","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Until the fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment:</p>\n<ul>\n<li>Restrict access to the VCO web interface to trusted administrative networks.</li>\n<li>Monitor the VCO for accesses from known malicious source IPs.</li>\n<li>Monitor for unexpected outbound network activity from the VCO host.</li>\n<li>Review recent administrator activity for unexpected changes.</li>\n</ul>"}],"value":"Until the fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment:\n\n\n\n  *  Restrict access to the VCO web interface to trusted administrative networks.\n\n  *  Monitor the VCO for accesses from known malicious source IPs.\n\n  *  Monitor for unexpected outbound network activity from the VCO host.\n\n  *  Review recent administrator activity for unexpected changes."}],"x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","assignerShortName":"Arista","cveId":"CVE-2026-17191","datePublished":"2026-07-27T16:41:17.436Z","dateReserved":"2026-07-24T19:03:13.728Z","dateUpdated":"2026-07-27T17:29:45.538Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-27 17:16:35","lastModifiedDate":"2026-07-27 18:16:53","problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":{"cvssMetricV40":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"PRESENT","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.1,"impactScore":5.3}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-27T17:29:37.640962Z","id":"CVE-2026-17191","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"17191","Ordinal":"1","Title":"VeloCloud Orchestrator Flow Metrics API SQL Injection","CVE":"CVE-2026-17191","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"17191","Ordinal":"1","NoteData":"An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections.\n\n\n\n\nThis issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.","Type":"Description","Title":"VeloCloud Orchestrator Flow Metrics API SQL Injection"}]}}}