A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.
To be vulnerable, CV-CUE UI must be enabled and running. The status can be audited with the command "cvpi status aware":
[root@]# cvpi status aware
Executing command. This may take some time...
Completed 1/1 discovered actions
primary components total:1 running:1 disabled:0
secondary components total:1 running:1 disabled:0
tertiary components total:1 running:1 disabled:0
There is no mitigation or workaround available for this issue.
CVE-2026-101157 has been fixed in the following releases:
- 2026.2.1 and later releases