Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-102157 has been fixed in the following releases: - 2026.2.1 and later releases
Vendor Workaround
There is no mitigation or workaround available for this issue.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arista
Arista cloudvision Cue |
|
| Vendors & Products |
Arista
Arista cloudvision Cue |
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under specific attack conditions, to access another user's transient data. | |
| Title | Security Advisory 0190 | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:02:04.283Z
Reserved: 2026-09-28T17:41:09.358Z
Link: CVE-2026-102157
Updated: 2026-10-06T20:02:00.515Z
Status : Awaiting Analysis
Published: 2026-10-06T20:17:10.700
Modified: 2026-10-07T13:38:48.657
Link: CVE-2026-102157
No data.
OpenCVE Enrichment
Updated: 2026-10-09T08:32:41Z
-
CWE-639
Authorization Bypass Through User-Controlled Key