CVE-2026-102158

Summary

Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksCloudVision CUE2022.2.0 <= 2026.2.0affected

Weaknesses

  • CWE-74: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Workarounds

There is no mitigation or workaround available for this issue.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References