CVE-2026-101153: Security Advisory 0188
On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CloudVision Portalto a version that resolves this vulnerability.Fixed in 1.4.3 - Upgrade
Upgrade
CloudVision Sensorto a version that resolves this vulnerability.Fixed in 2026.1.3 - Upgrade
Upgrade
CloudVision Sensorto a version that resolves this vulnerability.Fixed in 2026.2.1
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires an authenticated user with sufficiently high privileges. The provided information does not indicate that unauthenticated or low-privileged users can exploit it.
What systems and data are at risk?
Affected on-premises CloudVision Portal and CloudVision Sensor deployments are in scope. Successful exploitation can allow extraction of unintended data from the Sensor.
What are the practical impact and exploitation conditions?
The issue is remotely reachable, requires high privileges, and has high attack complexity. Its listed impact includes high confidentiality, integrity, and availability effects, with scope changed.