Arista Networks: 24 Vulnerabilities Disclosed Together in Wi-Fi APs and CloudVision
Key findings • Arista Networks disclosed 24 vulnerabilities on October 6, 2026, affecting Wi-Fi access points and CloudVision platforms. • Vulnerabilities range from Medium to Critical severi…

Key findings
- Arista Networks disclosed 24 vulnerabilities on October 6, 2026, affecting Wi-Fi access points and CloudVision platforms.
- Vulnerabilities range from Medium to Critical severity, with multiple High-severity flaws enabling RCE and DoS.
- CloudVision backend, authentication, and file management are impacted by critical and high-severity flaws.
- Stored XSS and path traversal vulnerabilities in CloudVision could lead to session hijacking and unauthorized data access.
- SSO and OIDC configuration issues present risks of authentication bypass and redirection attacks.
- Affected Arista products include Wi-Fi access points and CloudVision Portal/Sensor; prompt patching is advised.
On October 6, 2026, Arista Networks disclosed a significant batch of 24 vulnerabilities affecting its Wi-Fi access points and CloudVision platforms. These vulnerabilities, all disclosed on the same day, range in severity from Low to Critical, with a notable cluster of High and Critical severity flaws impacting core functionalities such as remote code execution, denial of service, and unauthorized access. This coordinated disclosure highlights potential risks for organizations relying on Arista's network infrastructure.
Several vulnerabilities center on the Arista Wi-Fi access points, particularly those with Captive Portal enabled. CVE-2026-102169 and CVE-2026-102168, both rated Medium, allow unauthenticated wireless clients to crash the captive portal service via crafted HTTP requests, leading to temporary or persistent denial of service. More severe are the High-severity flaws: CVE-2026-102167 and CVE-2026-102165, which could allow unauthenticated attackers to crash services or achieve remote code execution on the access point's wired uplink or capture services, respectively. CVE-2026-102163, a High-severity vulnerability, targets the Wireless Intrusion Prevention System (WIPS), allowing RF-proximate attackers to crash the sensor service or potentially achieve RCE. Additionally, CVE-2026-102162, another High-severity flaw, affects the wireless gateway service, potentially leading to a denial-of-service condition through stack overflow. A Low-severity vulnerability, CVE-2026-102164, involves memory content disclosure under specific VXLAN tunneling and L2-proxy configurations.
The CloudVision platform is also heavily impacted, with several critical and high-severity vulnerabilities. CVE-2026-102159 (Critical) and CVE-2026-102161 (High) involve access control flaws in the CV-CUE backend, potentially exposing sensitive location information, disrupting services, or allowing attackers to gain administrative session privileges by forging source IP addresses. CVE-2026-102160, a High-severity OS command injection vulnerability, allows authenticated Super Users to execute arbitrary commands via crafted backup requests. Several cross-site scripting (XSS) vulnerabilities, including stored XSS in CVE-2026-101158 (High), CVE-2026-101157 (High), and CVE-2026-101156 (High), could lead to session hijacking or compromise of authenticated user sessions. Path traversal vulnerabilities (CVE-2026-101153, High) and file system read/write vulnerabilities (CVE-2026-101155, Critical; CVE-2026-101154, High) allow authenticated users to access unintended data or files. Other CloudVision vulnerabilities include SQL injection (CVE-2026-102158, Medium), insecure direct object reference (CVE-2026-102157, Medium), LDAP injection (CVE-2026-102156, Medium), and XML External Entity (XXE) injection (CVE-2026-102155, High).
The batch also includes vulnerabilities related to Single Sign-On (SSO) and OpenID Connect (OIDC) configurations. CVE-2026-102152 (Medium) is an open redirect vulnerability, while CVE-2026-102151 (High) involves a flaw in the SSO login flow that could redirect authentication material to an attacker-controlled URL. CVE-2026-102150 (Medium) and CVE-2026-101149 (Medium) relate to insufficient validation of OIDC bearer token and provider configurations, respectively, potentially allowing requests to arbitrary destinations.
Arista Networks has provided advisories detailing the affected products and versions. Users are strongly recommended to consult these advisories and apply the necessary patches and updates to mitigate the risks associated with these vulnerabilities. The wide range of affected components and the severity of some flaws underscore the importance of prompt remediation for all Arista customers.
This coordinated disclosure of 24 vulnerabilities across Arista's Wi-Fi access points and CloudVision platforms presents a significant security challenge. The vulnerabilities, ranging from denial-of-service to remote code execution and sensitive data exposure, necessitate immediate attention from network administrators. Organizations should prioritize patching and configuration reviews to safeguard their Arista deployments against potential exploitation.
Key findings include:
- 24 vulnerabilities disclosed on the same day across Arista Wi-Fi APs and CloudVision.
- Multiple vulnerabilities allow for Remote Code Execution (RCE) and Denial of Service (DoS).
- Critical and High severity flaws impact CloudVision's backend, authentication, and file management.
- Stored XSS and path traversal vulnerabilities affect CloudVision user sessions and data access.
- SSO and OIDC configuration flaws could lead to authentication bypass or redirection attacks.
- Affected products include Arista Wi-Fi access points and CloudVision Portal/Sensor.