Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-101149 has been fixed in the following releases: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train - 2025.3.4 and later releases in the 2025.3.x train
Vendor Workaround
There is no configuration-based mitigation for this issue. However, operators can consider switching to an alternative non-OIDC SSO login method, if feasible. Additionally, restrict AAA settings and Account Management configuration permissions to trusted personnel only.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient validation of OIDC SSO provider configuration could allow a user with specific high privileges to direct requests to arbitrary destinations. | |
| Title | Security Advisory 0186 | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T19:51:18.383Z
Reserved: 2026-09-28T08:30:31.034Z
Link: CVE-2026-101149
Updated: 2026-10-06T19:51:14.208Z
Status : Received
Published: 2026-10-06T20:17:08.773
Modified: 2026-10-06T20:17:08.773
Link: CVE-2026-101149
No data.
OpenCVE Enrichment
Updated: 2026-10-06T21:15:06Z
-
CWE-918
Server-Side Request Forgery (SSRF)