VDB

CVE-2026-86106

CVE-2026-86106 PUBLISHED CVSS 9.6 CRITICAL

Reported by Arista · Published September 16, 2026

An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.

Risk Scores

CVSS 3.1
9.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Arista NetworksVeloCloud Edge1.0.0.0, 5.2.0.0, 6.1.0.0
Arista NetworksVeloCloud Edge1.0.0.0, 5.2.0.0, 6.1.0.0

Timeline

  • Sep 16, 2026 Coalition ESS Score
  • Sep 16, 2026 CVE Published
  • Sep 16, 2026 CVE Updated
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
  • Oct 3, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score

References

  • vendor-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›