Impact
The vulnerability stems from insufficient validation of the OIDC SSO provider configuration, allowing a user with high‑privilege access to reconfigure the provider to redirect users to arbitrary URLs. While the advisory does not explicitly mention phishing or credential theft, the ability to change redirect targets could be used to send users to malicious sites, which is inferred from the nature of open redirection flaws.
Affected Systems
Affected product is Arista Networks CloudVision Portal. Vulnerable versions include releases from the 2026.2.x train starting at 2026.2.1, the 2026.1.x train starting at 2026.1.3, and the 2025.3.x train starting at 2025.3.4. No other versions are marked as impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting no known public exploitation yet. Exploitation requires a user with high administrative privileges capable of editing the OIDC provider configuration; it is not exploitable by a remote attacker lacking such access. The redirect could lead to compromised user sessions or data exposure, an outcome inferred from the redirect ability but not explicitly confirmed in the advisory.
OpenCVE Enrichment