CVE-2026-86106: Security Advisory 0179
An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VeloCloud Edgeto a version that resolves this vulnerability.Fixed in 5.2.7.0 - Upgrade
Upgrade
VeloCloud Edgeto a version that resolves this vulnerability.Fixed in 6.1.5.0 - Upgrade
Upgrade
VeloCloud Edgeto a version that resolves this vulnerability.Fixed in 6.4.2 - Upgrade
Upgrade
VeloCloud Edgeto a version that resolves this vulnerability.Fixed in 7.0.0 - Compensating control
Restrict network access to the private HA interconnect so that unauthenticated actors cannot reach it.
Event History
Frequently Asked Questions
Which deployments are exposed?
Edge units with HA enabled are exposed if an unauthenticated actor can obtain network access to the private HA interconnect.
What access does an attacker need?
The attacker needs network access to the private HA interconnect. No authentication, privileges, or user interaction are required according to the supplied vector.
What is the potential impact of successful exploitation?
An attacker may trigger sensitive HA peer functions without verification, which could result in elevated command execution on affected Edge units. The provided severity vector indicates high confidentiality, integrity, and availability impact.