No analysis available yet.
Vendor Solution
CVE-2026-101157 has been fixed in the following releases: - 2026.2.1 and later releases
Vendor Workaround
There is no mitigation or workaround available for this issue.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services. | |
| Title | Security Advisory 0192 | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:05:36.991Z
Reserved: 2026-09-28T08:30:31.034Z
Link: CVE-2026-101157
Updated: 2026-10-06T20:05:32.923Z
Status : Received
Published: 2026-10-06T20:17:09.983
Modified: 2026-10-06T21:17:01.997
Link: CVE-2026-101157
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')