SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-17191

CRITICAL · CVSS 9.1 EPSS 2.83% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

An input validation vulnerability in the API component of the orchestrator allows authenticated users to manipulate backend queries, potentially leading to unauthorized data access and unintended outbound network connections. Organizations using this orchestrator should prioritize remediation efforts due to the critical severity of the flaw, which poses significant risks to data integrity and network security. While no known exploits have been reported in customer environments, proactive measures are essential to mitigate potential threats.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-17191
Severity
CRITICAL
CVSS
9.1
EPSS
2.83%

Original NVD Description

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.