Description
Insufficient validation of request in login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the user's browser to an arbitrary external site upon completion of the authentication process.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Open URL Redirection
Action: Update System
AI Analysis

Impact

Insufficient validation of the request during the CloudVision Portal login flow allows a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the user’s browser to an arbitrary external site after authentication completes. This open‑redirect flaw (CWE‑601) can enable phishing, malware downloads, or credential theft if the target site hosts malicious content.

Affected Systems

The flaw is present in Arista Networks’ CloudVision Portal in all releases prior to 2026.2.1 in the 2026.2.x train, 2026.1.3 in the 2026.1.x train, and 2025.3.4 in the 2025.3.x train.

Risk and Exploitability

The CVSS score of 5.3 denotes a moderate severity. Exploration of the EPSS score indicates it is not publicly available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation. Nevertheless, because the attacker only needs to craft a malicious link and relies on a user to click it, the risk is mainly social engineering; patching remains prudent to prevent eventual exploitation.

Generated by OpenCVE AI on October 6, 2026 at 20:24 UTC.

Remediation

Vendor Solution

CVE-2026-101151 has been fixed in the following releases: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train - 2025.3.4 and later releases in the 2025.3.x train


Vendor Workaround

No mitigation exists for this issue.


OpenCVE Recommended Actions

  • Upgrade the CloudVision Portal to 2026.2.1 or later, 2026.1.3 or later, or 2025.3.4 or later releases which contain the fix.
  • If an immediate upgrade is not feasible, restrict or validate redirect URLs to approved internal domains, or remove redirect parameters from the login flow to eliminate the open redirect.
  • Disable or audit any custom login redirect settings, ensuring that certificates or whitelists are enforced to prevent malicious external redirects.

Generated by OpenCVE AI on October 6, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Insufficient validation of request in login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the user's browser to an arbitrary external site upon completion of the authentication process.
Title Security Advisory 0187
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-10-06T19:50:22.629Z

Reserved: 2026-09-28T08:30:31.034Z

Link: CVE-2026-101151

cve-icon Vulnrichment

Updated: 2026-10-06T19:50:19.449Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:09.093

Modified: 2026-10-06T20:17:09.093

Link: CVE-2026-101151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:30:05Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')