TL;DR
Arista has patched six flaws in the CloudVision CUE (CV-CUE) backend for its WiFi software. The worst is CVE-2026-102159, a critical Arista CloudVision CUE vulnerability with a CVSS score of 9.8. Admins should upgrade to WiFi version 2026.2.1.
- Total: 6 CVEs
- Severity: 1 Critical · 4 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-102159
- Action: Apply the latest security updates now
Tired of noisy CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-102159 | 9.8 | Security Advisory 0190 | Not exploited |
| CVE-2026-102161 | 8.8 | Security Advisory 0190 | Not exploited |
| CVE-2026-102155 | 8.5 | Security Advisory 0190 | Not exploited |
| CVE-2026-102160 | 7.2 | Security Advisory 0190 | Not exploited |
| CVE-2026-102158 | 6.5 | Security Advisory 0190 | Not exploited |
| CVE-2026-102157 | 5.9 | Security Advisory 0190 | Not exploited |
Why It Matters
CV-CUE manages Arista wireless networks, so it holds data about users and devices. Two of the bugs need no login at all. Meanwhile, a third lets an attacker run commands on the server. Arista’s advisory does not report any exploitation in the wild or a public proof-of-concept.
How the Attacks Work
Unauthenticated Access
CVE-2026-102159 is an access-control flaw. According to Arista Security Advisory 190, it “may allow an unauthenticated network attacker to access functionality intended only for internal services.” Arista adds that success “may expose sensitive location information or disrupt affected services.”
CVE-2026-102161 (CVSS 8.8) works on an adjacent network. An attacker can forge their source IP address and “gain an administrative session privileges on the CV-CUE backend.” Setups behind a reverse proxy that forwards client headers also face this risk.
Authenticated Flaws
The other four bugs require a login. CVE-2026-102155 (CVSS 8.5) is an XML External Entity flaw that can leak local files. Next, CVE-2026-102160 (CVSS 7.2) lets a Super User inject OS commands through a crafted backup request. CVE-2026-102158 is a SQL injection that hurts availability. Finally, CVE-2026-102157 is an IDOR bug that can expose another user’s transient data.
Affected Versions
Every Arista CloudVision CUE vulnerability in this batch needs the backend to be active. In Arista’s words, “CV-CUE backend (wifimanager) must be enabled and running.” Most of the bugs date back to WiFi version 2021.2.0. CVE-2026-102158 starts in 2022.2.0, and CVE-2026-102159 starts in 2022.3.0.
Patch and Mitigation Steps
Upgrade to WiFi version 2026.2.1, which fixes all six flaws. First, though, confirm your exposure. The advisory notes that admins can run “cvpi status wifimanager” to check whether the backend is running.
Until you patch, limit network access to the backend to trusted hosts. Also check that any reverse proxy does not pass client IP headers through unchecked. These steps reduce risk while you fix this Arista CloudVision CUE vulnerability.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!