CVE-2026-102159 PUBLISHED

Security Advisory 0190

Assigner: Arista
Reserved: 28.09.2026 Published: 06.10.2026 Updated: 06.10.2026

An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected services.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Arista Networks
Product CloudVision CUE
Versions Default: unaffected
  • affected from 2022.3.0 to 2026.2.0 (incl.)

Affected Configurations

To be vulnerable, CV-CUE backend (wifimanager) must be enabled and running. To inspect the status of wifimanager:

[root@]# cvpi status wifimanager Executing command. This may take some time... Completed 1/1 discovered actions primary components total:1 running:1 disabled:0

Workarounds

There is no mitigation or workaround available for this issue.

Solutions

CVE-2026-102159 has been fixed in the following releases: - 2026.2.1 and later releases

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE

Impacts

  • CAPEC-115 Authentication Bypass