Description
On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.
Published: 2026-10-06
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Unintended Data Extraction via Path Traversal
Action: Patch Now
AI Analysis

Impact

The vulnerability is a path traversal flaw that allows an authenticated user with sufficient high privileges to access files that are not intended to be exposed. By manipulating file paths, the attacker can read sensitive data stored in the CloudVision Sensor, potentially leaking configuration or monitoring information.

Affected Systems

This flaw affects Arista Networks CloudVision Portal versions prior to 2026.2.1 (2026.2.x train) and prior to 2026.1.3 (2026.1.x train). It also impacts CloudVision Sensor versions prior to 1.4.3 within the 1.4.x train. The vulnerability exists on both on‑premises deployments of the portal and standalone sensor components.

Risk and Exploitability

The CVSS score of 7.2 classifies the issue as high severity, but the EPSS score is not available, indicating no publicly reported exploit data. The vendor lists the vulnerability under the Common Weakness enumeration CWE‑22. Attack requires authenticated, high‑privilege access to the portal or sensor. Once authenticated, the path traversal can be used to read files outside the intended directory, potentially exposing confidential sensor data. The vulnerability is not currently present in the CISA KEV catalog.

Generated by OpenCVE AI on October 6, 2026 at 20:23 UTC.

Remediation

Vendor Solution

CVE-2026-101153 has been fixed in the following releases: CloudVision Portal: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train CloudVision Sensor: - 1.4.3 and later releases in the 1.4.x train


Vendor Workaround

There is no reliable mitigation other than stopping the sensor component completely, which would prevent all functionality dependent on it from working. To stop the sensor, execute the following command on the CloudVision or Sensor VM: # Stop sensor completely: cvpi stop sensor To undo this and to start the sensor again use: # Start sensor: cvpi start sensor


OpenCVE Recommended Actions

  • Apply the vendor‑provided patch by updating CloudVision Portal to version 2026.2.1 or later, or 2026.1.3 or later, and CloudVision Sensor to version 1.4.3 or later.
  • If an immediate patch cannot be applied, stop the sensor component by running 'cvpi stop sensor' to eliminate the attack surface until the update can be installed, noting that this disables sensor‑dependent functionality.
  • Reduce the number of users with high‑privilege access to the CloudVision Portal and Sensor to limit the potential for exploitation.

Generated by OpenCVE AI on October 6, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.
Title Security Advisory 0188
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-10-06T19:49:31.675Z

Reserved: 2026-09-28T08:30:31.034Z

Link: CVE-2026-101153

cve-icon Vulnrichment

Updated: 2026-10-06T19:49:28.163Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:09.400

Modified: 2026-10-06T20:17:09.400

Link: CVE-2026-101153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:30:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')