CVE-2026-101158: Arista Networks Cloudvision Portal

High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.

Affected products

  • Arista Networks Cloudvision Portal: version 2026.2.0 only; from 2026.1.0, up to and including 2026.1.2; from 2025.3.0, up to and including 2025.3.3; from 1.0.0, before 2025.3.0 (fixed in 2025.3.0)

Published 2026-10-06. Last modified 2026-10-07.