Hackers Exploit VeloCloud Orchestrator Command Injection Vulnerability in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Security researchers have issued a warning about a critical command injection vulnerability that is being actively exploited in on-premises VeloCloud Orchestrator (VCO) deployments. This vulnerability, tracked as CVE-2026-16812, allows remote attackers to access privileged internal functions and potentially take control of the VeloCloud Orchestrator host.

The flaw has received the highest severity score of 10.0 in both CVSS v3.1 and CVSS v4.0. It is classified under CWE-78, which refers to the improper neutralization of special elements used in an operating system command. Such weaknesses can permit malicious input to be interpreted as a system command.

VeloCloud Orchestrator is used to manage SD-WAN environments, including connected VeloCloud Edge devices, network configurations, certificates, and other sensitive operational data. A successful attack could compromise the confidentiality, integrity, and availability of both the orchestrator and the information it manages.

Exploit VCO Command Injection Vulnerability

According to the security advisory, the vulnerable functionality was designed for internal use only; however, it is accessible remotely in affected on-premises VCO installations.

Importantly, attackers do not need VCO tenant or operator credentials to exploit this vulnerability they only require network access to the VCO web interface, which is exposed by default.

Affected versions include VCO 5.2.x releases before 5.2.3.14, VCO 6.1.x releases before 6.1.3.4, VCO 6.4.x releases before 6.4.2.4, and VCO 7.0.x releases before 7.0.0.1.

Organizations should verify the exact release version, as products not listed in the advisory are unaffected. End-of-support software versions have not been assessed. Hosted and Dedicated VCO services were patched before the public notice. The issue impacts only on-premises VeloCloud Orchestrator deployments.

Other products, such as VeloCloud Gateway, VeloCloud Edge, and hosted VCO offerings, as well as a broad range of Arista EOS-based products, are not affected.

Administrators should upgrade immediately to a fixed release. Patches are available in VCO versions 5.2.3.14 and later, 6.1.3.4 and later, and 6.4.2.4 and later. Customers running unsupported release trains should contact the Arista Technical Assistance Center for upgrade guidance.

Until patches are installed, organizations should restrict access to the VCO web interface to trusted administrative networks. They should also monitor the VCO host for suspicious inbound requests, unexpected outbound HTTP or HTTPS traffic, unexplained configuration changes, and unusual maintenance operations.

There is no single indicator that confirms a compromise. However, administrators should investigate web requests that include unusual URL path components, encoded characters, references to local services, or unusually high request volumes.

It’s advisable to review backend application logs, operating system logs, database logs, and file-system timestamps for any unusual activity.

The advisory identified three IP addresses that have been observed in attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Organizations should block these addresses as necessary and check historical logs for any connections from them.

If a compromise is suspected, incident responders should preserve relevant logs before remediation. Since an exploited orchestrator may expose managed VeloCloud Edge devices, organizations should rotate credentials, validate device states, review administrator actions, and restore affected systems only from trusted sources.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.