{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 192 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24808-security-advisory-0192"
      }
    ],
    "title": "Security Advisory 192",
    "tracking": {
      "current_release_date": "2026-10-06T07:37:32Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 192",
      "initial_release_date": "2026-10-06T07:37:32Z",
      "revision_history": [
        {
          "date": "2026-10-06T07:37:32Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "WiFi version 2025.2.0",
                    "product": {
                      "name": "WiFi version 2025.2.0",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "WiFi version 2026.2.1",
                    "product": {
                      "name": "WiFi version 2026.2.1",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "WiFi version 2021.2.0",
                    "product": {
                      "name": "WiFi version 2021.2.0",
                      "product_id": "CSAFPID-2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "WiFi"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-101156",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1782052"
      },
      "notes": [
        {
          "category": "description",
          "text": "A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensitive data, modify configurations, or disrupt managed wireless services.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "#### CVE-2026-101156 and CVE-2026-101157\n\nTo be vulnerable to CVE-2026-101156 and CVE-2026-101157, CV-CUE UI must be enabled and running. The status can be audited with the command \"`cvpi status aware`\". Here is an example output of that command that indicates the system is vulnerable:\n\n```\n[root@]# cvpi status aware \nExecuting command. This may take some time... \nCompleted 1/1 discovered actions \nprimary components total:1 running:1 disabled:0 \nsecondary components total:1 running:1 disabled:0 \ntertiary components total:1 running:1 disabled:0\n  \n```",
          "title": "1782052: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-1"
        ],
        "fixed": [
          "CSAFPID-0"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-101156"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version 2026.2.1",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in WiFi version 2025.2.0",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "mitigation",
          "details": "There is no mitigation or workaround available for both issues."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-101156"
    },
    {
      "cve": "CVE-2026-101157",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1802841"
      },
      "notes": [
        {
          "category": "description",
          "text": "A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "To be vulnerable to CVE-2026-101157, CV-CUE UI must be enabled and running. The status can be audited with the command \"`cvpi status aware`\". Here is an example output of that command that indicates the system is vulnerable:\n\n```\n[root@]# cvpi status aware \nExecuting command. This may take some time... \nCompleted 1/1 discovered actions \nprimary components total:1 running:1 disabled:0 \nsecondary components total:1 running:1 disabled:0 \ntertiary components total:1 running:1 disabled:0\n  \n```",
          "title": "1802841: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-2"
        ],
        "fixed": [
          "CSAFPID-0"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-101157"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version 2026.2.1",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in WiFi version 2021.2.0",
          "product_ids": [
            "CSAFPID-2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-2",
            "CSAFPID-0"
          ]
        }
      ],
      "title": "CVE-2026-101157"
    }
  ]
}