File System Exposure in Arista's Network Provisioning Image Repository
CVE-2026-101154
8.6HIGH
What is CVE-2026-101154?
An authenticated remote attacker with specific permissions can exploit inadequate access controls to gain unauthorized read or write access to files within the Arista Network Provisioning Image Repository. This vulnerability stems from the ability to send specially crafted requests and upload files that can compromise the integrity of the platform's file system. As such, sensitive data may be exposed or altered, thereby risking overall system security.
Affected Version(s)
CloudVision Portal CloudVision Portal, virtual appliance or physical appliance 2026.2.0
CloudVision Portal CloudVision Portal, virtual appliance or physical appliance 2026.1.0 <= 2026.1.2
CloudVision Portal CloudVision Portal, virtual appliance or physical appliance 2025.3.0 <= 2025.3.3
