PT-2026-96680 · Vmware · Velocloud Orchestrator

CVE-2026-93952

·

Published

2026-09-22

·

Updated

2026-10-01

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VeloCloud Orchestrator versions 5.2.3.15 and earlier VeloCloud Orchestrator versions 6.1.3.7 and earlier VeloCloud Orchestrator versions 6.4.2.7 and earlier VeloCloud Orchestrator versions 7.0.0.2 and earlier
Description An improper input validation issue in on-premises VeloCloud Orchestrator (VCO) allows a remote, unauthenticated attacker to access privileged internal functionality and impact the VCO host. This issue is actively exploited in the wild and specifically affects installations where Edge devices use certificate-based authentication. An attacker with network access to the VCO web interface and the public portion of the VeloCloud Edge certificate can compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages without requiring administrator or operator credentials. Successful exploitation may allow an attacker to gain a high-value position within the enterprise network-management infrastructure and potentially pivot to managed Edge devices.
Recommendations Update VeloCloud Orchestrator versions 5.2.x to 5.2.3.16 or later. Update VeloCloud Orchestrator versions 6.4.x to 6.4.2.8 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability for versions 6.1.x and 7.0.x. Restrict access to the VCO web interface to trusted administrative networks to minimize the risk of exploitation. Monitor nginx logs, suspicious files, and outbound connections to known malicious IP addresses for indicators of compromise.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15063
CVE-2026-93952

Affected Products

Velocloud Orchestrator