GPU VulnDB

Database/Firmware, BMC & network fabric

Arista CloudVision Portal: unvalidated Fileserver upload stores XSS that hijacks admin sessions

CVSS 9.3CVE-2026-101158Firmware, BMC & network fabriccurated

Impact

CloudVision Portal is the management plane for the Arista fabric that carries east-west traffic between GPU nodes and the storage network. An authenticated user who only holds file-upload rights can plant stored script that runs in the browser of any other CloudVision user who views it, including an administrator. Arista scores the scope change as high in both confidentiality and integrity: taking over an admin session means control over switch configuration and change deployment for the whole fabric, so a low-privilege operator account becomes a path to re-provisioning or disrupting tenant-crossing network paths. There is no GPU-node compromise here, but fabric config control is enough to isolate, mirror or blackhole traffic for an entire cluster.

Who can reach it

An authenticated CloudVision user with file upload privileges, reaching the portal over the management network; a second CloudVision user must then view the stored content (the CVSS vector requires passive user interaction).

What to do

Upgrade CloudVision Portal to a fixed release per Arista security advisory 0185; CVP upgrades restart the portal cluster services, so schedule a management-plane maintenance window - the switches keep forwarding, but streaming telemetry and change deployment pause. Until then, restrict file-upload privileges to accounts that need them and treat the portal as sensitive to session hijack. The advisory, not this entry, is the source for exact fixed versions.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.