CVE-2026-101157 PUBLISHED

Security Advisory 0192

Assigner: Arista
Reserved: 28.09.2026 Published: 06.10.2026 Updated: 06.10.2026

A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
CVSS Score: 9.3

Product Status

Vendor Arista Networks
Product CloudVision CUE
Versions Default: unaffected
  • affected from 2021.2.0 to 2026.2.0 (incl.)

Affected Configurations

To be vulnerable, CV-CUE UI must be enabled and running. The status can be audited with the command "cvpi status aware":

[root@]# cvpi status aware Executing command. This may take some time... Completed 1/1 discovered actions primary components total:1 running:1 disabled:0 secondary components total:1 running:1 disabled:0 tertiary components total:1 running:1 disabled:0

Workarounds

There is no mitigation or workaround available for this issue.

Solutions

CVE-2026-101157 has been fixed in the following releases: - 2026.2.1 and later releases

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE

Impacts

  • CAPEC-86 XSS Using HTTP Query Strings