{"uid":"cap_YXVLLCyWsLIbqAol_TZdL","slug":"tenjin-security-brief-velocloud-orchestrator-cve-2026-16812-faf71f41","name":"Tenjin Security Brief: VeloCloud Orchestrator CVE-2026-16812","description":"Arista says CVE-2026-16812 is a CVSS 10 OS command injection flaw in VeloCloud Orchestrator On-Prem, actively exploited with no VCO credentials required.","url":"https://tenjin.blog/api/read/security-briefs/security-briefs-daily-velocloud-orchestrator-was-exposed-by-default","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"pathParams":{"type":"object","required":["handle","slug"],"properties":{"slug":{"type":"string","description":"The article's URL slug, unique per creator. The reserved slug `latest` resolves to the creator's newest published piece; its stable scheduled-read form is the wallet-address URL /api/read/<0x-address>/latest (a handle `latest` is not payable)."},"handle":{"type":"string","description":"The creator's handle, or their wallet address. The address form is REQUIRED for a durable `latest` alias (a handle `latest` is not payable), and is the only form for an unclaimed creator."}}},"queryParams":{"type":"object","required":[],"properties":{},"additionalProperties":false}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_e0ziJ-gk_vkFIjy5zS6L6","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Retrieves a paid security brief about the critical CVE-2026-16812 OS command injection vulnerability in VeloCloud Orchestrator On-Prem, including exploitation details and Arista's advisory.","exampleAgentPrompt":"Pull up the Tenjin security brief on the VeloCloud Orchestrator vulnerability — I want to read about the CVSS 10 OS command injection flaw Arista flagged as actively exploited.","exampleUseCases":[{"title":"Security team CVE triage briefing","prompt":"Get me the Tenjin brief on CVE-2026-16812 in VeloCloud Orchestrator — we need to understand if it's unauthenticated and what the exploitation status is so we can prioritize patching."},{"title":"Threat intelligence daily digest","prompt":"Fetch the latest Tenjin security brief on the VeloCloud Orchestrator exposure — I'm building a daily threat intel summary and need the key details on this CVSS 10 command injection issue."},{"title":"Executive vulnerability summary","prompt":"Read the Tenjin article on the VeloCloud Orchestrator OS command injection flaw and give me a quick summary of the risk — specifically whether credentials are needed to exploit it."}],"resultDescription":"Returns the full text content of the Tenjin security brief covering CVE-2026-16812: a CVSS 10 OS command injection vulnerability in VeloCloud Orchestrator On-Prem, including Arista's advisory details, active exploitation status, and the fact that no VCO credentials are required to exploit it.","failureModes":["Article slug or handle mismatch returns 404 not found","Payment of 0.1 USDC not fulfilled results in 402 Payment Required","Handle resolves to wrong creator, returning unrelated content","Network timeout if tenjin.blog is temporarily unavailable"],"whenToPreferThis":"Choose this endpoint when you need a concise, paid security brief specifically about CVE-2026-16812 and VeloCloud Orchestrator On-Prem vulnerabilities. Prefer it over generic news searches when you want a curated, expert-written summary with exploitation context, CVSS scoring, and vendor advisory details in a single structured read.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:55:23.241Z","isFirstParty":false}