GPU VulnDB

Database/Firmware, BMC & network fabric

Arista CloudVision Portal: OIDC configuration accepts arbitrary destinations, letting an admin aim CVP requests outward

CVSS 5.1CVE-2026-101149Firmware, BMC & network fabric+1 more CVEscurated

Impact

CVP does not validate the endpoints given in its OIDC single sign-on provider configuration or its OIDC bearer token configuration, so an administrator can make the CVP server issue requests to destinations of their choosing. On a management appliance that sits inside the management VLAN, that turns CVP into a request relay toward hosts an outside attacker cannot reach directly, and it can send authentication traffic somewhere the operator does not control. Arista assigned two ids for the two configuration paths - CVE-2026-101149 (SSO provider config) and CVE-2026-101150 (bearer token config) - under one advisory with the same score and the same fix. Impact is bounded by the fact that only an already highly privileged CVP user can change this configuration; the CVSS scores it as crossing a trust boundary (SC:L) rather than as data loss.

Who can reach it

Remote over the network to the CVP configuration interface, authenticated as a user with specific high privileges (CVSS PR:H). No user interaction.

What to do

Upgrade CVP per Arista security advisory 0186 - the advisory holds the fixed versions, which this record does not state. The action is a CVP patch and service restart on the management appliance; nothing to do on switches or GPU nodes. Interim control is limiting who holds the CVP roles that can edit SSO configuration and watching egress from the CVP host.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-101150

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.