CVE-2026-86106 PUBLISHED

Security Advisory 0179

Assigner: Arista
Reserved: 05.09.2026 Published: 16.09.2026 Updated: 16.09.2026

An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Arista Networks
Product VeloCloud Edge
Versions Default: unaffected
  • affected from 1.0.0.0 to 5.2.0.0 (excl.)
  • affected from 5.2.0.0 to 5.2.7.0 (excl.)
  • affected from 6.1.0.0 to 6.1.5.0 (excl.)
  • affected from 6.4.0.0 to 6.4.2.0 (excl.)

Affected Configurations

The vulnerability requires HA to be enabled and the attacker to have Layer 2 network access to the dedicated HA interconnect.

Workarounds

Use dedicated port-to-port connections between HA pairs. Avoid extending the HA interconnect through shared switches or VLANs. Restrict physical and network access to HA interfaces.

Solutions

The following VeloCloud Edge releases contain the fix: - 5.2.7.0 and later in the 5.2.x train - 6.1.5.0 and later in the 6.1.x train - 6.4.2 and later in the 6.4.x train - 7.0.0 and later

No hotfixes are available for this issue.

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE

Impacts

  • CAPEC-115 Authentication Bypass