A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensitive data, modify configurations, or disrupt managed wireless services.
Advisories

No advisories yet.

Fixes

Solution

CVE-2026-101156 has been fixed in the following releases: - 2026.2.1 and later releases


Workaround

There is no mitigation or workaround available for this issue.

History

Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensitive data, modify configurations, or disrupt managed wireless services.
Title Security Advisory 0192
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 6.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-10-06T20:05:03.281Z

Reserved: 2026-09-28T08:30:31.034Z

Link: CVE-2026-101156

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:09.837

Modified: 2026-10-06T20:17:09.837

Link: CVE-2026-101156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses