Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-101153 has been fixed in the following releases: CloudVision Portal: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train CloudVision Sensor: - 1.4.3 and later releases in the 1.4.x train
Vendor Workaround
There is no reliable mitigation other than stopping the sensor component completely, which would prevent all functionality dependent on it from working. To stop the sensor, execute the following command on the CloudVision or Sensor VM: # Stop sensor completely: cvpi stop sensor To undo this and to start the sensor again use: # Start sensor: cvpi start sensor
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor. | |
| Title | Security Advisory 0188 | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T19:49:31.675Z
Reserved: 2026-09-28T08:30:31.034Z
Link: CVE-2026-101153
Updated: 2026-10-06T19:49:28.163Z
Status : Received
Published: 2026-10-06T20:17:09.400
Modified: 2026-10-06T20:17:09.400
Link: CVE-2026-101153
No data.
OpenCVE Enrichment
Updated: 2026-10-06T20:30:05Z