XML External Entity Injection Vulnerability in Spectralight Application by Arista
CVE-2026-102155

7.1HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-102155?

The Spectralight application by Arista has a vulnerability that allows authenticated users to exploit XML External Entity (XXE) injection. This can result in unauthorized access to local files, leading to data leaks and a potential denial of service. Attackers can craft malicious XML requests that, when processed by the application, may expose sensitive files or disrupt service functionality.

Affected Version(s)

CloudVision CUE CloudVision CUE on-premises, virtual appliance or physical appliance 2021.2.0 <= 2026.2.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.