A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
Advisories

No advisories yet.

Fixes

Solution

CVE-2026-101158 has been fixed in the following releases: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train - 2025.3.4 and later releases in the 2025.3.x train


Workaround

There is no mitigation available for this vulnerability. However, operators should ensure that roles with file upload permissions are restricted to trusted users. Review any role that has "Read and Write" permission on: Bug Alert Management, File, Packaging, Image Repository. Navigate to Settings → Roles to review role permissions, and Settings → Users to ensure only trusted users are assigned to those roles.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
Title Security Advisory 0185
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-10-06T19:51:46.864Z

Reserved: 2026-09-28T08:30:31.035Z

Link: CVE-2026-101158

cve-icon Vulnrichment

Updated: 2026-10-06T19:51:42.687Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:10.127

Modified: 2026-10-06T20:17:10.127

Link: CVE-2026-101158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:30:05Z

Weaknesses