What is CVE-2026-16812?
This is an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem that allows a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator. Immediate patching and network-level access restrictions are strongly recommended.
Azərbaycanca: Arista VeloCloud Orchestrator On-Prem-də uzaqdan hücumçuya əmr yeridilməsi (OS command injection) vasitəsilə imtiyazlı daxili funksiyalara çıxış və host səviyyəsində məxfilik, bütövlük və əlçatanlığa təsir imkanı verən boşluqdur. Bu zəiflik xüsusilə on-premises mühitlərdəki VeloCloud Orchestrator qurğularını hədəf alır. Dərhal yeniləmə tətbiq edilməli və şəbəkə səviyyəsində giriş nəzarəti sərtləşdirilməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ1
What type of vulnerability is CVE-2026-16812 in Arista VeloCloud Orchestrator On-Prem, and what can it lead to?
It is an OS command injection vulnerability. Successful exploitation allows a remote attacker to access privileged internal functionality and compromise the confidentiality, integrity, and availability of the VCO host.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.