Get real-time updates on Telegram
CVE-2026-101154: CloudVision Portal 2026.2.0, 2026.1.0 through 2026.1.2, 2025.3.0 through 2025.3.3, 2018.1.0 to before 2025.3.0
CVE-2026-101154. CVSS 3.1 base score 7.2 (HIGH, Vendor/CNA).
Affected technology
CloudVision Portal · 2026.2.0, 2026.1.0 through 2026.1.2, 2025.3.0 through 2025.3.3, 2018.1.0 to before 2025.3.0
Arista Networks
Description’s affected range: through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · High privileges required · No user interaction required
What an attacker can do
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository. Vendor/CNA’s CVSS 4.0 assessment (base score 8.6/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-22
- CCR priority
- 28.8 /100 (P4)
- CVSS 3.1
- 7.2 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 02:34:12.333111+00:00 UTC
- GitHub Advisory Database · Source record · observed 2026-10-07 02:36:03.777225+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-101154.html