XML External Entity Injection Vulnerability in Spectralight Application by Arista
CVE-2026-102155
7.1HIGH
What is CVE-2026-102155?
The Spectralight application by Arista has a vulnerability that allows authenticated users to exploit XML External Entity (XXE) injection. This can result in unauthorized access to local files, leading to data leaks and a potential denial of service. Attackers can craft malicious XML requests that, when processed by the application, may expose sensitive files or disrupt service functionality.
Affected Version(s)
CloudVision CUE CloudVision CUE on-premises, virtual appliance or physical appliance 2021.2.0 <= 2026.2.0
