Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-101156 has been fixed in the following releases: - 2026.2.1 and later releases
Vendor Workaround
There is no mitigation or workaround available for this issue.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensitive data, modify configurations, or disrupt managed wireless services. | |
| Title | Security Advisory 0192 | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:05:03.281Z
Reserved: 2026-09-28T08:30:31.034Z
Link: CVE-2026-101156
Updated: 2026-10-06T20:04:58.763Z
Status : Received
Published: 2026-10-06T20:17:09.837
Modified: 2026-10-06T21:17:01.870
Link: CVE-2026-101156
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')