VDB
CVE-2026-86106
CVE-2026-86106
PUBLISHED
CVSS 9.6 CRITICAL
Reported by Arista · Published September 16, 2026
An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.
Risk Scores
CVSS 3.1
9.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arista Networks | VeloCloud Edge | 1.0.0.0, 5.2.0.0, 6.1.0.0 |
| Arista Networks | VeloCloud Edge | 1.0.0.0, 5.2.0.0, 6.1.0.0 |
Timeline
- Sep 16, 2026 Coalition ESS Score
- Sep 16, 2026 CVE Published
- Sep 16, 2026 CVE Updated
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 3, 2026 EPSS Score
- Oct 6, 2026 EPSS Score