← All Advisories

Arista VCO insufficient input validation allows Enterprise Standard Admin to send requests to internal services

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-17192

Key Details

CVECVE-2026-17192
CVSS Score / Version8.5 (High) / CVSS v3.1
Updated2026-07-30
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is low; availability impact is none.
Classified asCWE-918 (Server-Side Request Forgery (SSRF))

What to Know

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin.

This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-17192
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-17192