CVE-2026-101150: Arista Networks Cloudvision Portal
Medium severity, CVSS 4.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Insufficient validation of OIDC bearer token configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.
Affected products
- Arista Networks Cloudvision Portal: version 2026.2.0 only; from 2026.1.0, up to and including 2026.1.2; from 2025.3.0, up to and including 2025.3.3; from 2023.3.0, before 2025.3.0 (fixed in 2025.3.0)
Published 2026-10-06. Last modified 2026-10-07.