CVE-2026-101154: Arista Networks Cloudvision Portal

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository.

Affected products

  • Arista Networks Cloudvision Portal: version 2026.2.0 only; from 2026.1.0, up to and including 2026.1.2; from 2025.3.0, up to and including 2025.3.3; from 2018.1.0, before 2025.3.0 (fixed in 2025.3.0)

Published 2026-10-06. Last modified 2026-10-07.