A security update addressing a vulnerability discovered in Arista products has been released.
The affected product is VeloCloud Orchestrator (VCO) On-Prem.
Affected Versions are 5.2.3.15 And earlier, 6.1.3.7 And earlier, 6.4.2.7 And earlier, and 7.0.0.2 And earlier.
CVE-2026-93952 is a vulnerability that allows an unauthenticated remote threat actor (an external threat actor who is not logged in) to access internal functions requiring privileges, potentially affecting VCO hosts.
The patch was provided through the latest update.
The fixed versions are VeloCloud Orchestrator (VCO) 5.2.3.16 And 6.4.2.8.
Arista has advised users to update to the latest version with the Vulnerability Patch in accordance with the instructions on the reference site.