Summary
CVE-2026-16812 is a critical OS command injection vulnerability (CWE-78) in Arista VeloCloud Orchestrator (VCO) On-Prem, carrying the maximum CVSS v3.1 score of 10.0. The flaw exposes privileged internal functionality — intended to be accessible only from within the system — to unauthenticated remote attackers over the network, enabling full compromise of the orchestrator host and all SD-WAN infrastructure it manages. Arista has confirmed active exploitation in the wild and released patched versions for all affected on-prem branches.
Technical details
- Root cause: Improper Neutralization of Special Elements used in an OS Command (CWE-78): internal VCO functionality that should never be network-accessible is exposed via the on-prem web interface, allowing unauthenticated attackers to inject and execute OS commands on the host.
- Trigger conditions: No credentials or user interaction required; the vulnerable endpoint is directly reachable over HTTPS from the network.
- Attack vector: Fully remote and unauthenticated (AV:N/AC:L/PR:N/UI:N); no prior foothold or account is needed to trigger exploitation.
- Impact: Full high-impact compromise of confidentiality, integrity, and availability (C:H/I:H/A:H), with scope change (S:C) — meaning the impact propagates beyond the VCO host itself to all SD-WAN edges and gateways managed by the orchestrator.
Affected software
- Arista VeloCloud Orchestrator On-Prem 5.2.0 through 5.2.3.13
- Arista VeloCloud Orchestrator On-Prem 6.1.0 through 6.1.3.3
- Arista VeloCloud Orchestrator On-Prem 6.4.0 through 6.4.2.3
- Arista VeloCloud Orchestrator On-Prem 7.0.0
Note: Hosted and Dedicated VCO deployments were patched by Arista prior to public disclosure of this advisory. On-prem instances remain the primary at-risk population.
Severity
CVSS v3.1 Base Score: 10.0 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate — apply vendor patches: Upgrade to the appropriate fixed version for your installed branch:
- VCO 5.2.x → upgrade to 5.2.3.14 or later
- VCO 6.1.x → upgrade to 6.1.3.4 or later
- VCO 6.4.x → upgrade to 6.4.2.4 or later
- VCO 7.0.x → upgrade to 7.0.0.1 or later
- If immediate patching is not feasible: Restrict all inbound access to the VCO web interface to trusted administrative networks only; block access from untrusted IP ranges at the network perimeter.
- Monitor the VCO host for unexpected outbound network activity and review access logs for anomalous URL patterns, encoded characters, or unexpected command execution activity.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

