Description
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
Published: 2026-10-06
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Credential Interception
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Single Sign‑On (SSO) login flow of Arista Networks CloudVision Portal. Insufficient validation of URL parameters allows an attacker to craft a malicious link that, when clicked by a legitimate user, causes the identity provider to deliver authentication data to a URL controlled by the attacker. This flaw, which aligns with CWE‑601 (Open Redirect), enables credential theft or session hijacking without requiring any prior authentication with CloudVision.

Affected Systems

Arista Networks CloudVision Portal is affected in all releases prior to 2026.2.1, 2026.1.3, and 2025.3.4. Any deployment of older builds that has not applied these updates is vulnerable.

Risk and Exploitability

The CVSS base score of 7.6 indicates a high severity vulnerability. Because no EPSS value is available, the precise likelihood of exploitation cannot be quantified, and the vulnerability is not enumerated in the CISA KEV catalog. Attackers can exploit this flaw remotely and unauthenticated by simply enticing users to open the malicious URL. Once executed, the attacker can obtain authentication material and potentially gain unauthorized access to the CloudVision environment, compromising both confidentiality and integrity of user sessions.

Generated by OpenCVE AI on October 6, 2026 at 20:24 UTC.

Remediation

Vendor Solution

CVE-2026-101152 has been fixed in the following releases: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train - 2025.3.4 and later releases in the 2025.3.x train


Vendor Workaround

No mitigation exists for this issue.


OpenCVE Recommended Actions

  • Apply the latest Arista CloudVision firmware that includes the security fix (2026.2.1, 2026.1.3, or 2025.3.4 or newer).
  • If an immediate upgrade is infeasible, restrict the SSO endpoint so that only trusted, internal URLs can be used for authentication callbacks to prevent malicious redirects from being processed.
  • Configure and monitor the SSO logs to detect unexpected redirect attempts and verify that callback URLs are limited to known, authorized domains.

Generated by OpenCVE AI on October 6, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
Title Security Advisory 0187
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-10-06T19:49:57.474Z

Reserved: 2026-09-28T08:30:31.034Z

Link: CVE-2026-101152

cve-icon Vulnrichment

Updated: 2026-10-06T19:49:52.785Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:09.243

Modified: 2026-10-06T20:17:09.243

Link: CVE-2026-101152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:30:05Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')