{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-86106","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-09-05T01:54:43.258Z","datePublished":"2026-09-16T10:12:55.587Z","dateUpdated":"2026-09-16T17:53:47.977Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-16T10:25:43.381Z"},"title":"Security Advisory 0179","descriptions":[{"lang":"en","value":"An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.</p>"}]}],"affected":[{"vendor":"Arista Networks","product":"VeloCloud Edge","defaultStatus":"unaffected","versions":[{"version":"1.0.0.0","lessThan":"5.2.0.0","status":"affected","versionType":"custom"},{"version":"5.2.0.0","lessThan":"5.2.7.0","status":"affected","versionType":"custom"},{"version":"6.1.0.0","lessThan":"6.1.5.0","status":"affected","versionType":"custom"},{"version":"6.4.0.0","lessThan":"6.4.2.0","status":"affected","versionType":"custom"}],"platforms":["VeloCloud Edge"]}],"configurations":[{"lang":"en","value":"The vulnerability requires HA to be enabled and the attacker to have Layer 2 network access to the dedicated HA interconnect.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The vulnerability requires HA to be enabled and the attacker to have Layer 2 network access to the dedicated HA interconnect.</p>"}]}],"workarounds":[{"lang":"en","value":"Use dedicated port-to-port connections between HA pairs. Avoid extending the HA interconnect through shared switches or VLANs. Restrict physical and network access to HA interfaces.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Use dedicated port-to-port connections between HA pairs. Avoid extending the HA interconnect through shared switches or VLANs. Restrict physical and network access to HA interfaces.</p>"}]}],"solutions":[{"lang":"en","value":"The following VeloCloud Edge releases contain the fix:\n- 5.2.7.0 and later in the 5.2.x train\n- 6.1.5.0 and later in the 6.1.x train\n- 6.4.2 and later in the 6.4.x train\n- 7.0.0 and later\n\nNo hotfixes are available for this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The following VeloCloud Edge releases contain the fix:</p>\n<ul>\n<li>5.2.7.0 and later in the 5.2.x train</li>\n<li>6.1.5.0 and later in the 6.1.x train</li>\n<li>6.4.2 and later in the 6.4.x train</li>\n<li>7.0.0 and later</li>\n</ul>\n<p>No hotfixes are available for this issue.</p>"}]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseScore":8.7,"baseSeverity":"HIGH"}}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24735-security-advisory-0179","tags":["vendor-advisory"]}],"impacts":[{"capecId":"CAPEC-115","descriptions":[{"lang":"en","value":"CAPEC-115 Authentication Bypass"}]}],"source":{"advisory":"Security Advisory 0179","discovery":"INTERNAL","defects":["BUG1833882"]},"datePublic":"2026-09-09T00:00:00.000Z"},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-16T17:52:49.256029Z","id":"CVE-2026-86106","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-16T17:53:47.977Z"}}]}}