CVE-2026-101158 PUBLISHED

Security Advisory 0185

Assigner: Arista
Reserved: 28.09.2026 Published: 06.10.2026 Updated: 06.10.2026

A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.3

Product Status

Vendor Arista Networks
Product CloudVision Portal
Versions Default: unaffected
  • Version 2026.2.0 is affected
  • affected from 2026.1.0 to 2026.1.2 (incl.)
  • affected from 2025.3.0 to 2025.3.3 (incl.)
  • affected from 1.0.0 to 2025.3.0 (excl.)

Affected Configurations

No specific configuration is required to be vulnerable to this issue. This vulnerability is present in the default configuration of affected releases.

Workarounds

There is no mitigation available for this vulnerability. However, operators should ensure that roles with file upload permissions are restricted to trusted users. Review any role that has "Read and Write" permission on: Bug Alert Management, File, Packaging, Image Repository. Navigate to Settings → Roles to review role permissions, and Settings → Users to ensure only trusted users are assigned to those roles.

Solutions

CVE-2026-101158 has been fixed in the following releases: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train - 2025.3.4 and later releases in the 2025.3.x train

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE

Impacts

  • CAPEC-86 XSS Using HTTP Query Strings