{"api_version":"1","generated_at":"2026-10-07T14:35:00+00:00","cve":"CVE-2026-101153","urls":{"html":"https://cve.report/CVE-2026-101153","api":"https://cve.report/api/cve/CVE-2026-101153.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-101153","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-101153"},"summary":{"title":"Security Advisory 0188","description":"On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.","state":"PUBLISHED","assigner":"Arista","published_at":"2026-10-06 20:17:09","updated_at":"2026-10-07 13:38:48"},"problem_types":["CWE-22","CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":[{"version":"4.0","source":"psirt@arista.com","type":"Secondary","score":"7.2","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"7.2","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H","data":{"baseScore":7.2,"baseSeverity":"HIGH","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H","version":"4.0"}},{"version":"3.1","source":"psirt@arista.com","type":"Secondary","score":"8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24804-security-advisory-0188","name":"https://www.arista.com/en/support/advisories-notices/security-advisory/24804-security-advisory-0188","refsource":"psirt@arista.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-101153","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101153","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Arista Networks","product":"CloudVision Portal","version":"affected 2026.2.0 custom","platforms":["CloudVision Portal, virtual appliance or physical appliance"]},{"source":"CNA","vendor":"Arista Networks","product":"CloudVision Portal","version":"affected 2026.1.0 2026.1.2 custom","platforms":["CloudVision Portal, virtual appliance or physical appliance"]},{"source":"CNA","vendor":"Arista Networks","product":"CloudVision Portal","version":"affected 2025.3.0 2025.3.3 custom","platforms":["CloudVision Portal, virtual appliance or physical appliance"]},{"source":"CNA","vendor":"Arista Networks","product":"CloudVision Portal","version":"affected 2025.2.0 2025.2.3 custom","platforms":["CloudVision Portal, virtual appliance or physical appliance"]},{"source":"CNA","vendor":"Arista Networks","product":"CloudVision Portal","version":"affected 2025.1.0 2025.1.4 custom","platforms":["CloudVision Portal, virtual appliance or physical appliance"]},{"source":"CNA","vendor":"Arista Networks","product":"CloudVision Portal","version":"affected 2024.3.0 2024.3.3 custom","platforms":["CloudVision Portal, virtual appliance or physical appliance"]},{"source":"CNA","vendor":"Arista Networks","product":"CloudVision Sensor","version":"affected 1.4.0 1.4.2 custom","platforms":["CloudVision Sensor"]},{"source":"CNA","vendor":"Arista Networks","product":"CloudVision Sensor","version":"affected 1.3.0 1.3.1 custom","platforms":["CloudVision Sensor"]},{"source":"CNA","vendor":"Arista Networks","product":"CloudVision Sensor","version":"affected 1.0.0 1.3.0 custom","platforms":["CloudVision Sensor"]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"CVE-2026-101153 has been fixed in the following releases:\n\nCloudVision Portal:\n- 2026.2.1 and later releases in the 2026.2.x train\n- 2026.1.3 and later releases in the 2026.1.x train\n\nCloudVision Sensor:\n- 1.4.3 and later releases in the 1.4.x train","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"There is no reliable mitigation other than stopping the sensor component completely, which would prevent all functionality dependent on it from working. To stop the sensor, execute the following command on the CloudVision or Sensor VM:\n\n# Stop sensor completely:\ncvpi stop sensor\n\nTo undo this and to start the sensor again use:\n\n# Start sensor:\ncvpi start sensor","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-101153","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-06T19:49:23.342532Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-06T19:49:31.675Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["CloudVision Portal, virtual appliance or physical appliance"],"product":"CloudVision Portal","vendor":"Arista Networks","versions":[{"status":"affected","version":"2026.2.0","versionType":"custom"},{"lessThanOrEqual":"2026.1.2","status":"affected","version":"2026.1.0","versionType":"custom"},{"lessThanOrEqual":"2025.3.3","status":"affected","version":"2025.3.0","versionType":"custom"},{"lessThanOrEqual":"2025.2.3","status":"affected","version":"2025.2.0","versionType":"custom"},{"lessThanOrEqual":"2025.1.4","status":"affected","version":"2025.1.0","versionType":"custom"},{"lessThanOrEqual":"2024.3.3","status":"affected","version":"2024.3.0","versionType":"custom"}]},{"defaultStatus":"unaffected","platforms":["CloudVision Sensor"],"product":"CloudVision Sensor","vendor":"Arista Networks","versions":[{"lessThanOrEqual":"1.4.2","status":"affected","version":"1.4.0","versionType":"custom"},{"lessThanOrEqual":"1.3.1","status":"affected","version":"1.3.0","versionType":"custom"},{"lessThan":"1.3.0","status":"affected","version":"1.0.0","versionType":"custom"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>No specific configuration is required to be vulnerable to this issue. This vulnerability is present in the default configuration of affected releases.</p>"}],"value":"No specific configuration is required to be vulnerable to this issue. This vulnerability is present in the default configuration of affected releases."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.</p>"}],"value":"On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor."}],"impacts":[{"capecId":"CAPEC-126","descriptions":[{"lang":"en","value":"CAPEC-126 Path Traversal"}]}],"metrics":[{"cvssV3_1":{"baseScore":8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV4_0":{"baseScore":7.2,"baseSeverity":"HIGH","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H","version":"4.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-06T19:38:07.896Z","orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista"},"references":[{"tags":["vendor-advisory"],"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24804-security-advisory-0188"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>CVE-2026-101153 has been fixed in the following releases:</p><p><strong>CloudVision Portal:</strong></p><ul><li>2026.2.1 and later releases in the 2026.2.x train</li><li>2026.1.3 and later releases in the 2026.1.x train</li></ul><p><strong>CloudVision Sensor:</strong></p><ul><li>1.4.3 and later releases in the 1.4.x train</li></ul>"}],"value":"CVE-2026-101153 has been fixed in the following releases:\n\nCloudVision Portal:\n- 2026.2.1 and later releases in the 2026.2.x train\n- 2026.1.3 and later releases in the 2026.1.x train\n\nCloudVision Sensor:\n- 1.4.3 and later releases in the 1.4.x train"}],"source":{"advisory":"Security Advisory 0188","defects":["BUG 1898011"],"discovery":"INTERNAL"},"title":"Security Advisory 0188","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>There is no reliable mitigation other than stopping the sensor component completely, which would prevent all functionality dependent on it from working. To stop the sensor, execute the following command on the CloudVision or Sensor VM:</p><pre># Stop sensor completely:\ncvpi stop sensor</pre><p>To undo this and to start the sensor again use:</p><pre># Start sensor:\ncvpi start sensor</pre>"}],"value":"There is no reliable mitigation other than stopping the sensor component completely, which would prevent all functionality dependent on it from working. To stop the sensor, execute the following command on the CloudVision or Sensor VM:\n\n# Stop sensor completely:\ncvpi stop sensor\n\nTo undo this and to start the sensor again use:\n\n# Start sensor:\ncvpi start sensor"}]}},"cveMetadata":{"assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","assignerShortName":"Arista","cveId":"CVE-2026-101153","datePublished":"2026-10-06T19:38:07.896Z","dateReserved":"2026-09-28T08:30:31.034Z","dateUpdated":"2026-10-06T19:49:31.675Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-06 20:17:09","lastModifiedDate":"2026-10-07 13:38:48","problem_types":["CWE-22","CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":{"cvssMetricV40":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.3,"impactScore":6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-06T19:49:23.342532Z","id":"CVE-2026-101153","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"101153","Ordinal":"1","Title":"Security Advisory 0188","CVE":"CVE-2026-101153","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"101153","Ordinal":"1","NoteData":"On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.","Type":"Description","Title":"Security Advisory 0188"}]}}}