An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

The following VeloCloud Edge releases contain the fix: - 5.2.7.0 and later in the 5.2.x train - 6.1.5.0 and later in the 6.1.x train - 6.4.2 and later in the 6.4.x train - 7.0.0 and later No hotfixes are available for this issue.


Workaround

Use dedicated port-to-port connections between HA pairs. Avoid extending the HA interconnect through shared switches or VLANs. Restrict physical and network access to HA interfaces.

History

Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.
Title Security Advisory 0179
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T10:25:43.381Z

Reserved: 2026-09-05T01:54:43.258Z

Link: CVE-2026-86106

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:43.783

Modified: 2026-09-16T11:16:43.783

Link: CVE-2026-86106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses