CVE-2026-101149: Arista Networks Cloudvision Portal

Medium severity, CVSS 4.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Insufficient validation of OIDC SSO provider configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.

Affected products

  • Arista Networks Cloudvision Portal: version 2026.2.0 only; from 2026.1.0, up to and including 2026.1.2; from 2025.3.0, up to and including 2025.3.3; from 2020.3.0, before 2025.3.0 (fixed in 2025.3.0)

Published 2026-10-06. Last modified 2026-10-07.