CVE-2026-16812
About
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
This functionality was intended to be for internal use only and is not intended to be remotely accessible.
Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.
This issue was discovered externally and is known to be actively exploited.
Rainforest analyst review
This is a flaw in on-premises VeloCloud Orchestrator (VCO) where functionality intended for internal use only is reachable by a remote attacker, letting them access privileged internal capabilities and impact the VCO host. The description ties the issue to OS command handling, and successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator and all the data it manages, so an attacker who reaches the exposed internal functionality can act against the host itself rather than merely reading data.
VeloCloud Orchestrator is the central management plane for a VeloCloud SD-WAN deployment, so it holds configuration and control over an organization's wide-area network edges; compromising it is compromising the brain of the network fabric. The vendor states this was discovered externally and is known to be actively exploited, and that hosted and dedicated VCO instances were patched ahead of the notice, which raises priority for on-prem operators. Apply the fix to on-premises VCO promptly, ensure the internal functionality and management interfaces are not exposed beyond trusted administrative networks, and given active exploitation, inspect the host for command execution and unauthorized changes and rotate credentials the orchestrator manages.
References
Related CVEs
Frequently asked questions
What is CVE-2026-16812?
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
How severe is CVE-2026-16812?
CVE-2026-16812 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2026-16812 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2026-16812?
Public advisories list the following as affected: velocloud orchestrator. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2026-16812?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
