CVE-2026-86109

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.

Scoring

Severity
HIGH
CVSS base score
7.5
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS probability
0.24%
CWE
CWE-347
Published
2026-09-16
Last modified
2026-09-17

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs