CVE-2026-101158
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Summary
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | CloudVision Portal | 2026.2.0 | affected |
| Arista Networks | CloudVision Portal | 2026.1.0 <= 2026.1.2 | affected |
| Arista Networks | CloudVision Portal | 2025.3.0 <= 2025.3.3 | affected |
| Arista Networks | CloudVision Portal | 1.0.0 < 2025.3.0 | affected |
Weaknesses
- CWE-79: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Workarounds
There is no mitigation available for this vulnerability. However, operators should ensure that roles with file upload permissions are restricted to trusted users. Review any role that has "Read and Write" permission on: Bug Alert Management, File, Packaging, Image Repository. Navigate to Settings → Roles to review role permissions, and Settings → Users to ensure only trusted users are assigned to those roles.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.