No analysis available yet.
Vendor Solution
CVE-2026-102155 has been fixed in the following releases: - 2026.2.1 and later releases
Vendor Workaround
There is no mitigation or workaround available for this issue.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service. | |
| Title | Security Advisory 0190 | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:01:43.823Z
Reserved: 2026-09-28T17:41:09.358Z
Link: CVE-2026-102155
Updated: 2026-10-06T20:01:39.219Z
Status : Received
Published: 2026-10-06T20:17:10.400
Modified: 2026-10-06T21:17:02.280
Link: CVE-2026-102155
No data.
OpenCVE Enrichment
No data.
-
CWE-611
Improper Restriction of XML External Entity Reference