CVE-2026-101153

Summary

On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksCloudVision Portal2026.2.0affected
Arista NetworksCloudVision Portal2026.1.0 <= 2026.1.2affected
Arista NetworksCloudVision Portal2025.3.0 <= 2025.3.3affected
Arista NetworksCloudVision Portal2025.2.0 <= 2025.2.3affected
Arista NetworksCloudVision Portal2025.1.0 <= 2025.1.4affected
Arista NetworksCloudVision Portal2024.3.0 <= 2024.3.3affected
Arista NetworksCloudVision Sensor1.4.0 <= 1.4.2affected
Arista NetworksCloudVision Sensor1.3.0 <= 1.3.1affected
Arista NetworksCloudVision Sensor1.0.0 < 1.3.0affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Workarounds

There is no reliable mitigation other than stopping the sensor component completely, which would prevent all functionality dependent on it from working. To stop the sensor, execute the following command on the CloudVision or Sensor VM:

Stop sensor completely:

cvpi stop sensor

To undo this and to start the sensor again use:

Start sensor:

cvpi start sensor

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References