CVE-2026-102161: Arista Networks Cloudvision Cue

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.

Affected products

  • Arista Networks Cloudvision Cue: from 2021.2.0, up to and including 2026.2.0

Published 2026-10-06. Last modified 2026-10-07.