VulnSea

cloudvision_cue vulnerabilities

CVEs whose affected-version data names the cloudvision_cue package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-102161High· 8.8
yesterday

An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges o…

An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges o…

▾ TwilightArista Networks · CloudVision CUEvia NVD
CVE-2026-101156High· 8.4
yesterday

A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration

A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user view…

▾ TwilightArista Networks · CloudVision CUEvia NVD
CVE-2026-102158Medium· 6.5
yesterday

Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability.

Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability.

▾ SunlitArista Networks · CloudVision CUEvia NVD
CVE-2026-101157High· 8.7
yesterday

A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content

A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may…

▾ TwilightArista Networks · CloudVision CUEvia NVD
CVE-2026-102157Medium· 5.9
yesterday

An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under specific attack conditions, to access another user's transient data.

An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under specific attack conditions, to access another user's transient data.

▾ SunlitArista Networks · CloudVision CUEvia NVD
CVE-2026-102155High· 8.5
yesterday

An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service.

An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service.

▾ TwilightArista Networks · CloudVision CUEvia NVD
CVE-2026-102160High· 7.2
yesterday

An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected ser…

An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected ser…

▾ TwilightArista Networks · CloudVision CUEvia NVD
CVE-2026-102159Critical· 9.8
yesterday

An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services

An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected…

▾ MidnightArista Networks · CloudVision CUEvia NVD
CVE-2026-102156Medium· 6.8
yesterday

Improper neutralization of Lightweight Directory Access Protocol (LDAP) authentication input may allow an unauthenticated network attacker, under high-complexity conditions, to inject queries against the configured directory service.

Improper neutralization of Lightweight Directory Access Protocol (LDAP) authentication input may allow an unauthenticated network attacker, under high-complexity conditions, to inject queries against the configured directory service.

▾ SunlitArista Networks · CloudVision CUEvia NVD
cloudvision_cue vulnerabilities (CVEs) · VulnSea