An OS command injection vulnerability (CVE-2026-16812) has been identified in VeloCloud Orchestrator (VCO), a product of Arista Networks.
Affected Versions include VeloCloud Orchestrator (VCO) versions prior to 5.2.3.14, Prior to 6.1.3.4, Prior to 6.4.2.4, And prior to 7.0.0.1.
Arista Networks has released a security update to address this vulnerability.
The latest update provides a Vulnerability Patch; users must update to the latest version that includes the Vulnerability Patch following the instructions on the reference site.