Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-102159: Arista CloudVision CUE backend lets outsiders access internal functions

CVE-2026-102159 · published 5 days ago
Summary

The backend component of Arista CloudVision CUE can be reached over the network without any login, allowing outsiders to use features meant only for internal services. This could let them view sensitive location data or cause service interruptions. Apply the vendor's security update and limit network access to the backend to trusted systems only.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
arista networks cloudvision cue <= 2026.2.0
Original advisory text
Security Advisory 0190
An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected services.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published6 Oct 2026
Updated11 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-102159 · MITRE
Track software like this
Free during beta