Insecure Direct Object Reference in Arista Networks CloudVision Product
CVE-2026-102157

6.8MEDIUM

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-102157?

An insecure direct object reference (IDOR) vulnerability exists in the CloudVision CUE file-serving interface. This flaw could potentially allow an authenticated network user to gain unauthorized access to another user's transient data under certain attack conditions. Organizations using the Arista CloudVision platform should evaluate their security configurations and take necessary steps to mitigate potential risks.

Affected Version(s)

CloudVision CUE CloudVision CUE on-premises, virtual appliance or physical appliance 2021.2.0 <= 2026.2.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.