CVE-2026-17192
HIGH NVDCVSS Score
8.5
Severity
HIGH
Source
NVD
Published
Jul 27, 2026
Description
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.