securityonline.info 7 Oct 2026, 01:48 UTC

Arista patches critical CV-CUE flaw that could expose WiFi network data

Arista patches critical CV-CUE flaw that could expose WiFi network data

ARISTA has released a patch for six flaws in the CloudVision CUE (CV-CUE) backend used with its WiFi software, with the most severe being CVE-2026-102159, rated 9.8 on CVSSv3. The administrator-facing advisory notes that CV-CUE manages Arista wireless networks and can hold sensitive data on users and devices. Of the six bugs, two allow unauthenticated access to functionality intended only for internal services, while others require a login.

In particular, CVE-2026-102159 is an unauthenticated access flaw that may let a network attacker reach internal services, potentially exposing location data or disrupting services. CVE-2026-102161 can let an attacker forge a source IP and gain administrative session privileges on the CV-CUE backend, including scenarios behind a reverse proxy that forwards client headers.

The remaining authenticated vulnerabilities include CVE-2026-102155 (XML External Entity, possible local file leakage), CVE-2026-102160 (Super User can inject OS commands via a crafted backup request), CVE-2026-102158 (SQL injection affecting availability), and CVE-2026-102157 (IDOR exposing another user’s transient data). Arista’s advisory indicates affected versions date back to WiFi 2021.2.0, with CVE-2026-102158 starting in 2022.2.0 and CVE-2026-102159 beginning in 2022.3.0.

The recommended fix is to upgrade to WiFi version 2026.2.1, after verifying exposure with the cvpi status wifimanager command, and to limit backend access to trusted hosts until patching. Arista reports no exploitation in the wild or public PoCs at the time of the advisory.

View full article

Article by CyberSIXT