Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-101155 has been fixed in the following releases: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train - 2025.3.4 and later releases in the 2025.3.x train
Vendor Workaround
There is no mitigation available for this vulnerability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Software Management Studio Software Repository. | |
| Title | Security Advisory 0189 | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:01:14.740Z
Reserved: 2026-09-28T08:30:31.034Z
Link: CVE-2026-101155
No data.
Status : Received
Published: 2026-10-06T20:17:09.703
Modified: 2026-10-06T20:17:09.703
Link: CVE-2026-101155
No data.
OpenCVE Enrichment
No data.