Impact
An input validation flaw in the Fileserver upload API can be exploited by an authenticated CloudVision user with upload rights to inject malicious JavaScript. The resulting stored XSS can hijack the web session of other users, potentially giving the attacker full administrative control over their account. The flaw is a classic reflected injection due to lack of sanitization of user‑submitted file metadata, which is precisely CWE‑79.
Affected Systems
Arista Networks CloudVision Portal is affected in all released versions prior to the patched releases: 2026.2.1, 2026.1.3, and 2025.3.4. Any environment running a CloudVision version before those builds carries the vulnerability. The insecure API endpoint is the file upload service used by the portal.
Risk and Exploitability
The calculated CVSS score of 9.3 indicates high severity, and while the EPSS score is not available, the lack of mitigation suggests that the vulnerability could be actively exploited if attackers obtain upload privileges. Given that the flaw requires authentication, the risk is limited to users with file‑upload rights, yet the impact is significant due to session hijack potential. No status in KEV indicates it is not yet a known exploited vulnerability, but the high score warrants proactive action.
OpenCVE Enrichment