CVE-2026-101153: Arista Networks Cloudvision Portal

High severity, CVSS 8.0. EPSS: 0.3% chance of exploitation in the next 30 days.

On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.

Affected products

  • Arista Networks Cloudvision Portal: version 2026.2.0 only; from 2026.1.0, up to and including 2026.1.2; from 2025.3.0, up to and including 2025.3.3; from 2025.2.0, up to and including 2025.2.3; from 2025.1.0, up to and including 2025.1.4; from 2024.3.0, up to and including 2024.3.3
  • Arista Networks Cloudvision Sensor: from 1.4.0, up to and including 1.4.2; from 1.3.0, up to and including 1.3.1; from 1.0.0, before 1.3.0 (fixed in 1.3.0)

Published 2026-10-06. Last modified 2026-10-07.