{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 185 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24801-security-advisory-0185"
      }
    ],
    "title": "Security Advisory 185",
    "tracking": {
      "current_release_date": "2026-10-05T20:27:38Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 185",
      "initial_release_date": "2026-10-05T20:27:38Z",
      "revision_history": [
        {
          "date": "2026-10-05T20:27:38Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version 2026.1.3",
                    "product": {
                      "name": "CloudVision Portal version 2026.1.3",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version 2025.3.4",
                    "product": {
                      "name": "CloudVision Portal version 2025.3.4",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version 1.0.0",
                    "product": {
                      "name": "CloudVision Portal version 1.0.0",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version 2026.2.1",
                    "product": {
                      "name": "CloudVision Portal version 2026.2.1",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version 2026.3.0",
                    "product": {
                      "name": "CloudVision Portal version 2026.3.0",
                      "product_id": "CSAFPID-0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "CloudVision Portal"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-101158",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1867488"
      },
      "notes": [
        {
          "category": "description",
          "text": "The vulnerability affects both CloudVision Portal (on-premises) and CloudVision-CUE (on-premises). CV-CUE is Arista\u2019s Wi-Fi management service and, in on-premises deployments, is hosted as a service on the CloudVision Portal on-premises platform. Because the affected component is used by both product deployments, customers running either CVP or CV-CUE should review the affected versions to assess their impact.\n\nA missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "No specific configuration is required to be vulnerable to this issue. This vulnerability is present in the default configuration of affected releases.",
          "title": "1867488: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-2"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-3",
          "CSAFPID-4"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-101158"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in CloudVision Portal version 2025.3.4",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in CloudVision Portal version 2026.1.3",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in CloudVision Portal version 2026.2.1",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in CloudVision Portal version 2026.3.0",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in CloudVision Portal version 1.0.0",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "mitigation",
          "details": "There is no mitigation available for this vulnerability. However, operators should ensure that roles with file upload permissions are restricted to trusted users.\n\nTo do this, review any role that has \"Read and Write\" permission on the following resources, and ensure that only trusted users are assigned to it:  \n\n* Bug Alert Management\n* File\n* Packaging\n* Image Repository\n\n1.  Navigate to **Settings ->** **Roles**, then click on the \"Pencil\" icon beside a role to edit it.\n\nFig 1: Roles settings page\n\n2. Identify any role that has \"Read and Write\" permission on the resources listed above.\n\nFig 2: Bug Alerts Management & File\n\n\t\n\nFig 3: Packaging\n\nFig 4: Image Repository\n\n3. Navigate to **Settings ->** **Users** and verify that only trusted users are assigned to those roles.\n\nFig 5: Users settings page"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-2",
            "CSAFPID-1",
            "CSAFPID-0",
            "CSAFPID-4",
            "CSAFPID-3"
          ]
        }
      ],
      "title": "CVE-2026-101158"
    }
  ]
}