CVE-2026-101150: medium-severity vulnerability in Arista Networks CloudVision Portal
Security Advisory 0186
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
Insufficient validation of OIDC bearer token configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Affected products
Arista Networks · CloudVision PortalRelated CVEs — Arista Networks CloudVision Portal
In the same product, most dangerous first.
CVE-2024-11186CRITICALOn affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premEPSS 0.8%CVE-2025-0505CRITICALOn Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system stateEPSS 0.7%CVE-2026-101155HIGHSecurity Advisory 0189EPSS 0.6%CVE-2026-101154HIGHSecurity Advisory 0189EPSS 0.6%CVE-2024-12378CRITICALOn affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.EPSS 0.5%CVE-2026-101152HIGHSecurity Advisory 0187EPSS 0.4%