CVE-2026-86108: Security Advisory 0181
Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch Security Advisory 0181
Event History
Frequently Asked Questions
Can an unauthenticated attacker exploit this directly?
The vulnerability requires high privileges and an authorized management request or configuration value. It is network-reachable, but the provided data does not indicate that unauthenticated access is sufficient.
Does exploitation require administrator interaction?
No user interaction is required. Exploitation is rated as high complexity, so the attacker must satisfy additional conditions beyond having the required privileges.
What could a successful attacker do?
Successful exploitation can result in operating-system command execution with elevated privileges on the affected VeloCloud Edge. The vulnerability is rated as having high impact on confidentiality, integrity, and availability, with scope changed.