Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-101158 has been fixed in the following releases: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train - 2025.3.4 and later releases in the 2025.3.x train
Vendor Workaround
There is no mitigation available for this vulnerability. However, operators should ensure that roles with file upload permissions are restricted to trusted users. Review any role that has "Read and Write" permission on: Bug Alert Management, File, Packaging, Image Repository. Navigate to Settings → Roles to review role permissions, and Settings → Users to ensure only trusted users are assigned to those roles.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions. | |
| Title | Security Advisory 0185 | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T19:51:46.864Z
Reserved: 2026-09-28T08:30:31.035Z
Link: CVE-2026-101158
Updated: 2026-10-06T19:51:42.687Z
Status : Received
Published: 2026-10-06T20:17:10.127
Modified: 2026-10-06T20:17:10.127
Link: CVE-2026-101158
No data.
OpenCVE Enrichment
Updated: 2026-10-06T20:30:05Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')