PT-2026-96680 · Vmware · Velocloud Orchestrator
CVE-2026-93952
·
Published
2026-09-22
·
Updated
2026-10-01
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VeloCloud Orchestrator versions 5.2.3.15 and earlier
VeloCloud Orchestrator versions 6.1.3.7 and earlier
VeloCloud Orchestrator versions 6.4.2.7 and earlier
VeloCloud Orchestrator versions 7.0.0.2 and earlier
Description
An improper input validation issue in on-premises VeloCloud Orchestrator (VCO) allows a remote, unauthenticated attacker to access privileged internal functionality and impact the VCO host. This issue is actively exploited in the wild and specifically affects installations where Edge devices use certificate-based authentication. An attacker with network access to the VCO web interface and the public portion of the VeloCloud Edge certificate can compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages without requiring administrator or operator credentials. Successful exploitation may allow an attacker to gain a high-value position within the enterprise network-management infrastructure and potentially pivot to managed Edge devices.
Recommendations
Update VeloCloud Orchestrator versions 5.2.x to 5.2.3.16 or later.
Update VeloCloud Orchestrator versions 6.4.x to 6.4.2.8 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for versions 6.1.x and 7.0.x.
Restrict access to the VCO web interface to trusted administrative networks to minimize the risk of exploitation.
Monitor nginx logs, suspicious files, and outbound connections to known malicious IP addresses for indicators of compromise.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Velocloud Orchestrator