Security Advisory

CVE-2026-17192

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-27 16:36:32
Last updated 2026-07-27 17:28:36
Assigner Arista
CVSS score not scored
State PUBLISHED

Description

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.