VYPR
Vendor

VeloCloud

Products
5
CVEs
5
Across products
6
Status
Private

Products

5

Recent CVEs

5
  • CVE-2020-3973HigJul 8, 2020
    risk 0.57cvss 8.8epss 0.01

    The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.

  • CVE-2026-86108HigSep 16, 2026
    risk 0.52cvss 8.0epss 0.01

    Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command…

  • CVE-2026-86109MedSep 16, 2026
    risk 0.43cvss 6.6epss 0.00

    The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to…

  • CVE-2026-86107MedSep 16, 2026
    risk 0.38cvss 5.9epss 0.00

    The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol only. A successful exploit can cause the affected process to…

  • CVE-2026-16812CriKEVJul 27, 2026
    risk 0.12cvss 10.0epss 0.02

    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator…