CVE-2026-86108: Arista Networks VeloCloud Edge

High severity, CVSS 8.0. EPSS: 0.6% chance of exploitation in the next 30 days.

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.

Affected products

  • Arista Networks VeloCloud Edge: from 6.4.0, before 6.4.2 (fixed in 6.4.2); from 6.1.0, before 6.1.5 (fixed in 6.1.5); from 5.2.0, before 5.2.7 (fixed in 5.2.7); from 0.0.0, before 5.2.0 (fixed in 5.2.0)

Published 2026-09-16. Last modified 2026-09-17.