Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-102161 has been fixed in the following releases: - 2026.2.1 and later releases
Vendor Workaround
There is no mitigation or workaround available for this issue.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend. | |
| Title | Security Advisory 0190 | |
| Weaknesses | CWE-290 CWE-798 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:04:10.245Z
Reserved: 2026-09-28T17:41:09.358Z
Link: CVE-2026-102161
No data.
Status : Received
Published: 2026-10-06T20:17:11.230
Modified: 2026-10-06T20:17:11.230
Link: CVE-2026-102161
No data.
OpenCVE Enrichment
No data.