CVE-2026-102155: Arista Networks Cloudvision Cue
High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service.
Affected products
- Arista Networks Cloudvision Cue: from 2021.2.0, up to and including 2026.2.0
Published 2026-10-06. Last modified 2026-10-07.