CVE-2026-101157: critical vulnerability in Arista Networks CloudVision CUE
Security Advisory 0192
Published
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Affected products
Arista Networks · CloudVision CUERelated CVEs — Arista Networks CloudVision CUE
In the same product, most dangerous first.
CVE-2026-102160HIGHSecurity Advisory 0190EPSS 1.4%CVE-2026-102159CRITICALSecurity Advisory 0190EPSS 0.4%CVE-2026-102155HIGHSecurity Advisory 0190EPSS 0.3%CVE-2026-101156MEDIUMSecurity Advisory 0192EPSS 0.3%CVE-2026-102156MEDIUMSecurity Advisory 0191EPSS 0.3%CVE-2026-102158HIGHSecurity Advisory 0190EPSS 0.3%