CVE-2026-17192

Severity CVSS v4.0:
MEDIUM
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
27/07/2026
Last modified:
27/07/2026

Description

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin.<br /> <br /> <br /> <br /> <br /> This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.