CVE-2026-17192
HIGH
NVD
CVSS Score
8.5
Severity
HIGH
Published
Jul 27, 2026
Vendor
unknown
Description
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.