Description
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
Published: 2026-10-06
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting allowing session hijack and escalation
Action: Immediate Patch
AI Analysis

Impact

An input validation flaw in the Fileserver upload API can be exploited by an authenticated CloudVision user with upload rights to inject malicious JavaScript. The resulting stored XSS can hijack the web session of other users, potentially giving the attacker full administrative control over their account. The flaw is a classic reflected injection due to lack of sanitization of user‑submitted file metadata, which is precisely CWE‑79.

Affected Systems

Arista Networks CloudVision Portal is affected in all released versions prior to the patched releases: 2026.2.1, 2026.1.3, and 2025.3.4. Any environment running a CloudVision version before those builds carries the vulnerability. The insecure API endpoint is the file upload service used by the portal.

Risk and Exploitability

The calculated CVSS score of 9.3 indicates high severity, and while the EPSS score is not available, the lack of mitigation suggests that the vulnerability could be actively exploited if attackers obtain upload privileges. Given that the flaw requires authentication, the risk is limited to users with file‑upload rights, yet the impact is significant due to session hijack potential. No status in KEV indicates it is not yet a known exploited vulnerability, but the high score warrants proactive action.

Generated by OpenCVE AI on October 6, 2026 at 20:27 UTC.

Remediation

Vendor Solution

CVE-2026-101158 has been fixed in the following releases: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train - 2025.3.4 and later releases in the 2025.3.x train


Vendor Workaround

There is no mitigation available for this vulnerability. However, operators should ensure that roles with file upload permissions are restricted to trusted users. Review any role that has "Read and Write" permission on: Bug Alert Management, File, Packaging, Image Repository. Navigate to Settings → Roles to review role permissions, and Settings → Users to ensure only trusted users are assigned to those roles.


OpenCVE Recommended Actions

  • Upgrade the CloudVision Portal to version 2026.2.1 or later, or to 2026.1.3 or 2025.3.4 in the appropriate train.
  • Immediately review and tighten role permissions, retaining file upload rights only for trusted users and eliminating any role that grants 'Read and Write' access to Bug Alert Management, File, Packaging, or Image Repository.
  • Verify that no other users with upload rights are present in the system and remove any unnecessary accounts.
  • Document all changes and keep a log of the version update for audit purposes.

Generated by OpenCVE AI on October 6, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
Title Security Advisory 0185
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-10-06T19:51:46.864Z

Reserved: 2026-09-28T08:30:31.035Z

Link: CVE-2026-101158

cve-icon Vulnrichment

Updated: 2026-10-06T19:51:42.687Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:10.127

Modified: 2026-10-06T20:17:10.127

Link: CVE-2026-101158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')