CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-101155: CloudVision Portal 2026.2.0, 2026.1.0 through 2026.1.2, 2025.3.0 through 2025.3.3, 2024.2.0 to before 2025.3.0

CVE-2026-101155. CVSS 3.1 base score 9.1 (CRITICAL, Vendor/CNA).

Affected technology

CloudVision Portal · 2026.2.0, 2026.1.0 through 2026.1.2, 2025.3.0 through 2025.3.3, 2024.2.0 to before 2025.3.0
Arista Networks

Description’s affected range: through specially crafted requests and/or crafted file uploads to the Software Management Studio Software Repository

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · High privileges required · No user interaction required

What an attacker can do

An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Software Management Studio Software Repository. Vendor/CNA’s CVSS 4.0 assessment (base score 8.6/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-22
CCR priority
36.4 /100 (P4)
CVSS 3.1
9.1 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H · Vendor/CNA
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-101155.html