Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-101152 has been fixed in the following releases: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train - 2025.3.4 and later releases in the 2025.3.x train
Vendor Workaround
No mitigation exists for this issue.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision. | |
| Title | Security Advisory 0187 | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T19:49:57.474Z
Reserved: 2026-09-28T08:30:31.034Z
Link: CVE-2026-101152
Updated: 2026-10-06T19:49:52.785Z
Status : Received
Published: 2026-10-06T20:17:09.243
Modified: 2026-10-06T20:17:09.243
Link: CVE-2026-101152
No data.
OpenCVE Enrichment
Updated: 2026-10-06T20:30:05Z