Description
Insufficient validation of OIDC SSO provider configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.
Published: 2026-10-06
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Open Redirection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from insufficient validation of the OIDC SSO provider configuration, allowing a user with high‑privilege access to reconfigure the provider to redirect users to arbitrary URLs. While the advisory does not explicitly mention phishing or credential theft, the ability to change redirect targets could be used to send users to malicious sites, which is inferred from the nature of open redirection flaws.

Affected Systems

Affected product is Arista Networks CloudVision Portal. Vulnerable versions include releases from the 2026.2.x train starting at 2026.2.1, the 2026.1.x train starting at 2026.1.3, and the 2025.3.x train starting at 2025.3.4. No other versions are marked as impacted.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting no known public exploitation yet. Exploitation requires a user with high administrative privileges capable of editing the OIDC provider configuration; it is not exploitable by a remote attacker lacking such access. The redirect could lead to compromised user sessions or data exposure, an outcome inferred from the redirect ability but not explicitly confirmed in the advisory.

Generated by OpenCVE AI on October 6, 2026 at 21:12 UTC.

Remediation

Vendor Solution

CVE-2026-101149 has been fixed in the following releases: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train - 2025.3.4 and later releases in the 2025.3.x train


Vendor Workaround

There is no configuration-based mitigation for this issue. However, operators can consider switching to an alternative non-OIDC SSO login method, if feasible. Additionally, restrict AAA settings and Account Management configuration permissions to trusted personnel only.


OpenCVE Recommended Actions

  • Apply the vendor patch updating to any supported release (2026.2.1 or later, 2026.1.3 or later, or 2025.3.4 or later).
  • If a patch cannot be applied immediately, disable OIDC SSO or switch to an alternative non‑OIDC SSO login method.
  • Restrict AAA settings and account management configuration permissions to trusted personnel only so that only authorized users can modify OIDC provider configuration.

Generated by OpenCVE AI on October 6, 2026 at 21:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Insufficient validation of OIDC SSO provider configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.
Title Security Advisory 0186
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-10-06T19:51:18.383Z

Reserved: 2026-09-28T08:30:31.034Z

Link: CVE-2026-101149

cve-icon Vulnrichment

Updated: 2026-10-06T19:51:14.208Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:08.773

Modified: 2026-10-06T20:17:08.773

Link: CVE-2026-101149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:15:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)