CVE-2026-102155

Summary

An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksCloudVision CUE2021.2.0 <= 2026.2.0affected

Weaknesses

  • CWE-611: CWE-611 Improper Restriction of XML External Entity Reference

Workarounds

There is no mitigation or workaround available for this issue.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References