CVE-2026-101154
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Summary
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | CloudVision Portal | 2026.2.0 | affected |
| Arista Networks | CloudVision Portal | 2026.1.0 <= 2026.1.2 | affected |
| Arista Networks | CloudVision Portal | 2025.3.0 <= 2025.3.3 | affected |
| Arista Networks | CloudVision Portal | 2018.1.0 < 2025.3.0 | affected |
Weaknesses
- CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Workarounds
There is no mitigation available for this vulnerability.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.