CVE-2026-101152: Arista Networks Cloudvision Portal

High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.

Affected products

  • Arista Networks Cloudvision Portal: version 2026.2.0 only; from 2026.1.0, up to and including 2026.1.2; from 2025.3.0, up to and including 2025.3.3; from 2021.1.0, before 2025.3.0 (fixed in 2025.3.0)

Published 2026-10-06. Last modified 2026-10-07.